A vulnerability was found in SourceCodester Simple Doctors Appointment System 1.0 . It has been declared as critical . This issue affects the function save_doctor of the file /save_file.php . The manipulation results in unrestricted upload. This vulnerability is identified as CVE-2026-19839 . The attack can be executed remotely. Additionally, an exploit exists.