PT-2026-55263 · Unknown · Red Sea Cloud Ehr

CVE-2024-14037

·

Published

2026-07-02

·

Updated

2026-07-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redsea Cloud eHR (affected versions not specified)
Description An arbitrary file upload flaw allows unauthenticated attackers to achieve remote code execution. By sending a multipart POST request to the 'PtFjk.mob' servlet endpoint, an attacker can upload a JSP webshell. The system fails to validate file extensions and MIME types, allowing the attacker to bypass security by spoofing the Content-Type as image/jpeg. The uploaded file is stored in a predictable path within the uploadfile directory and can be executed directly by the web server. Real-world exploitation was first observed on 2024-11-03 (UTC).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-14037

Affected Products

Red Sea Cloud Ehr