9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.
AI Analysis
Remote Code Execution vulnerability in Sourcecodester Covid-19 Contact Tracing System 1.0
Basic Information
ID
CVE-2025-66802
Source
mitre
Published
Jan 12, 2026 at 00:00
Modified
Jan 12, 2026 at 19:37
Affected Product
Vendor
Sourcecodester
Product
Sourcecodester Covid-19 Contact Tracing System
Version
1.0
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Sourcecodester
Product
Covid-19 Contact Tracing System
Version
1.0