Vulnerabilities
Vulnerable Software
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the server.
CVSS Score
8.8
EPSS Score
0.006
Published
2026-01-15
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor that enables arbitrary command execution on the server through a weaponized PHP script.
CVSS Score
8.8
EPSS Score
0.006
Published
2026-01-15
index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-08-06
index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-08-06
index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.
CVSS Score
5.4
EPSS Score
0.004
Published
2021-08-06


Contact Us

Shodan ® - All rights reserved