PT-2026-3034 · Unknown · Chikitsa Patient Management System

0Z09E

·

Publicado

2026-01-15

·

Atualizado

2026-01-20

·

CVE-2021-47758

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chikitsa Patient Management System version 2.0.2
Description The software contains an authenticated remote code execution issue. Attackers can upload malicious PHP plugins through the module upload functionality. Authenticated attackers can create and upload a ZIP plugin containing a PHP backdoor, enabling arbitrary command execution on the server via a weaponized PHP script. The vulnerable functionality involves uploading modules.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the module upload functionality.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-47758

Produtos afetados

Chikitsa Patient Management System