Impact
The HospitalManagementSystem accepts an "img" parameter in several controller functions and allows an attacker to supply arbitrary files without validating the file type or content. This flaw enables unrestricted upload of any file, including executable code. If an attacker uploads a malicious script to a web‑accessible location, it could be executed with the web server’s privileges, resulting in full compromise of the host. The weakness is characterized by CWE‑284 (Improper Access Control) and CWE‑434 (Unrestricted Upload of File with Dangerous Type).
Affected Systems
Onetwothreeneth’s HospitalManagementSystem is affected. The project follows a rolling release model and no specific versions are identified as fixed or vulnerable; the vulnerability exists in any release up to the commit 9ef91ed6007314b6473110ed699dff76d158f61d.
Risk and Exploitability
The CVSS score is 6.9 and the EPSS score is not available, indicating a moderate severity with uncertain exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the public disclosure of an exploit and the statement that the attack may be launched remotely, the likely attack vector is a remote HTTP request that includes a crafted "img" value. An attacker could therefore achieve execution of arbitrary code on the affected system.
OpenCVE Enrichment