VulnerabilityAnalyzed
CVE-2025-9772
A vulnerability was detected in RemoteClinic up to 2.0.
MEDIUM 5.5EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Performing manipulation of the argument image results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-434
- Affected
- remoteclinic/remote clinic
- Source
- cna@vuldb.com
References
- https://github.com/lan041221/cvec/issues/18Exploit, Third Party Advisory
- https://vuldb.com/?ctiid.322072Permissions Required, VDB Entry
- https://vuldb.com/?id.322072Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.640867Exploit, Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.640956Third Party Advisory, VDB Entry
- https://github.com/lan041221/cvec/issues/18Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.