CVE-2025-9772 is a critical unrestricted file upload vulnerability affecting RemoteClinic up to version 2.0, specifically within the /staff/edit.php file when manipulating the 'image' argument. This remote, low-complexity attack allows for complete compromise of confidentiality, integrity, and availability, as reflected by its CVSS score of 9.8. While the exploit is public, there is currently no evidence of active exploitation, nor are there readily available Metasploit or Nuclei modules, and it has garnered minimal community discussion or media coverage. This vulnerability exclusively impacts unsupported versions of the product.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0CPE matchmatch criteria | cpe:2.3:a:remoteclinic:remote_clinic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.