What is CVE-2026-19839?
This vulnerability exists in SourceCodester Simple Doctors Appointment System 1.0, affecting the save_doctor function in /save_file.php. It allows unrestricted file upload, potentially leading to remote code execution. As the exploit is publicly available, the system should be updated or temporarily taken offline.
Azərbaycanca: Bu zəiflik SourceCodester Simple Doctors Appointment System 1.0 proqramında aşkarlanıb və /save_file.php faylındakı save_doctor funksiyasına təsir edir. Məhdudiyyətsiz fayl yükləmə imkanı verir ki, uzaqdan kod icrasına səbəb ola bilər. İstismar ictimaiyyətə açıq olduğu üçün sistem dərhal yenilənməli və ya müvəqqəti olaraq dayandırılmalıdır.
Related CVEs
link basis: same weakness class CWE-434; shared vendor: SourceCodester
FAQ2
Which version of SourceCodester Simple Doctors Appointment System is affected by CVE-2026-19839?
This vulnerability affects version 1.0 of SourceCodester Simple Doctors Appointment System.
What risk does exploiting CVE-2026-19839 pose?
The unrestricted file upload capability can lead to remote code execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.