Impact
An unrestricted file upload flaw allows an attacker to upload a web shell to the server. This leads to arbitrary code execution from the web interface, compromising confidentiality, integrity, and availability of the site.
Affected Systems
Hospital Management System plugin from Mojoomla, version 47.0 (dated 20-11-2023) and earlier.
Risk and Exploitability
The vulnerability carries a CVSS score of 10, an EPSS of less than 1%, and is not listed in CISA KEV. Attackers can exploit it by using the plugin’s public upload interface to place a malicious file in a web‑accessible directory, then execute it.
OpenCVE Enrichment
EUVD