CVE-2025-9775

A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.php. The manipulation of the argument image results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used.
References
Link Resource
https://github.com/diy777/cve/issues/2 Exploit Third Party Advisory
https://vuldb.com/?ctiid.322075 Permissions Required VDB Entry
https://vuldb.com/?id.322075 Third Party Advisory VDB Entry
https://vuldb.com/?submit.640955 Third Party Advisory VDB Entry
https://github.com/diy777/cve/issues/2 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:remoteclinic:remote_clinic:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-01 11:15

Updated : 2025-09-04 16:00


NVD link : CVE-2025-9775

Mitre link : CVE-2025-9775

CVE.ORG link : CVE-2025-9775


JSON object : View

Products Affected

remoteclinic

  • remote_clinic
CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type