Vulnerability Description
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Covid-19 Contact Tracing System Project | Covid-19 Contact Tracing System | 1.0 |
Related Weaknesses (CWE)
References
- https://feedly.com/cve/CVE-2022-2746Not Applicable
- https://github.com/mtgsjr/CVE-2025-66802ExploitMitigationThird Party Advisory
FAQ
What is CVE-2025-66802?
CVE-2025-66802 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.
How severe is CVE-2025-66802?
CVE-2025-66802 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-66802?
Check the references section above for vendor advisories and patch information. Affected products include: Covid-19 Contact Tracing System Project Covid-19 Contact Tracing System.