RemoteClinic Unrestricted File Upload Vulnerability in Profile Edit Function

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in RemoteClinic versions through 2.0. The issue resides in the file '/staff/edit-my-profile.php', where inadequate validation of the 'image' parameter permits attackers to upload arbitrary files, including malicious scripts. This vulnerability can be exploited remotely, without any authentication, potentially leading to unauthorized code execution on the server.

Impact

Exploitation of this vulnerability allows attackers to upload and execute malicious scripts on the server, gaining unauthorized access and control. This could result in the compromise of sensitive data, unauthorized operations, and disruption of services.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/staff/edit-my-profile.php' with the 'image' parameter. The request must include a file named 'shell.php' containing a PHP payload that exploits the vulnerability by executing code on the server.

Remediation

No specific mitigation measures are known for this vulnerability.

Added: Sep 1, 2025, 11:19 AM
Updated: Sep 1, 2025, 11:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
7.5
exploitability
9.5
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.