PT-2023-1419 · Unknown · Nosh Chartingsystem

Charalampos Theodorou

·

Published

2023-02-01

·

Updated

2023-02-08

·

CVE-2023-24610

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NOSH version 4a5cfdb
Description The issue allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be bypassed, potentially enabling attackers to steal Protected Health Information due to the product's purpose for health charting. This is related to an unlimited file upload vulnerability in the Organization/Practice module of the New Open Source Health (NOSH) ChartingSystem, which can allow a remote attacker to execute arbitrary code and gain full control over the system.
Recommendations For NOSH version 4a5cfdb, consider disabling the "practice logo" upload feature until a patch is available to prevent the execution of arbitrary PHP code. Restrict access to the file upload functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00807
CVE-2023-24610

Affected Products

Nosh Chartingsystem