Impact
An identified weakness resides in the save_doctor routine of the Simple Doctors Appointment System’s /save_file.php endpoint, allowing any file to be uploaded without restriction. The flaw permits the storage of arbitrary file types through a manipulated request. This unrestricted upload capability is the core impact of the vulnerability.
Affected Systems
This vulnerability specifically targets SourceCodester Simple Doctors Appointment System version 1.0. No other vendors or components are indicated. The issue originates in the /save_file.php file that handles doctor profile uploads.
Risk and Exploitability
The CVSS score of 5.1 denotes medium severity for a remotely exploitable flaw that requires no authentication. EPSS data is unavailable, but the public availability of the exploit raises the likelihood of real‑world attacks. The vulnerability is not cataloged in CISA KEV. Typical exploitation involves an attacker sending a crafted multipart/form-data request to the /save_file.php endpoint to upload a file of any type, making remote access the attack vector.
OpenCVE Enrichment