9.6
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Description
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.
AI Analysis
Cross-Site Request Forgery (CSRF) vulnerability allowing arbitrary file upload
Basic Information
ID
CVE-2026-39620
Source
Patchstack
Published
Apr 8, 2026 at 08:30
Modified
Apr 14, 2026 at 14:16
Affected Product
Vendor
priyanshumittal
Product
Appointment
Affected Versions
priyanshumittal Appointment 0
CWE Classification
AI Assessment
AI Score
9.6 / 10
AI Severity
Critical
Vendor
priyanshumittal
Product
Appointment
Version
<= 3.5.5