CVE-2026-19839: Sourcecodester Simple Doctors Appointment System

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.

Affected products

Published 2026-08-14. Last modified 2026-08-18.