---
id: CVE-2022-28568
title: >-
  Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to
  RCE via Image upload from the administrator panel
summary: >-
  Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to
  RCE via Image upload from the administrator panel. An attacker can obtain
  remote command execution just by knowing the path where the images are stored.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: simple_doctor's_appointment_system_project
product: simple_doctor's_appointment_system
affected:
  - simple_doctor's_appointment_system = 1.0
published: '2022-05-04'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-28568'
references:
  - url: 'https://github.com/b3nj1-1/CVE/tree/main/CVE-2022-28568'
    label: cve@mitre.org
  - url: 'http://doctors.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://sourcecodetester.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/b3nj1-1/CVE/tree/main/CVE-2022-28568'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.03291
epssPercentile: 0.87957
ingestedAt: '2026-07-06T02:09:23.481Z'
---

## Overview

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

## Affected

- `simple_doctor's_appointment_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
