PT-2026-3034 · Unknown · Chikitsa Patient Management System
0Z09E
·
Publicado
2026-01-15
·
Atualizado
2026-01-20
·
CVE-2021-47758
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chikitsa Patient Management System version 2.0.2
Description
The software contains an authenticated remote code execution issue. Attackers can upload malicious PHP plugins through the module upload functionality. Authenticated attackers can create and upload a ZIP plugin containing a PHP backdoor, enabling arbitrary command execution on the server via a weaponized PHP script. The vulnerable functionality involves uploading modules.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the module upload functionality.
Exploit
Correção
RCE
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Chikitsa Patient Management System