Vulnerability Description
A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic results in unrestricted upload. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/freeloader9527/cve/issues/2
- https://vuldb.com/submit/792092
- https://vuldb.com/vuln/358237
- https://vuldb.com/vuln/358237/cti
FAQ
What is CVE-2026-6602?
CVE-2026-6602 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The man...
How severe is CVE-2026-6602?
CVE-2026-6602 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-6602?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.