PT-2026-55263 · Unknown · Red Sea Cloud Ehr
CVE-2024-14037
·
Published
2026-07-02
·
Updated
2026-07-02
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Redsea Cloud eHR (affected versions not specified)
Description
An arbitrary file upload flaw allows unauthenticated attackers to achieve remote code execution. By sending a multipart POST request to the 'PtFjk.mob' servlet endpoint, an attacker can upload a JSP webshell. The system fails to validate file extensions and MIME types, allowing the attacker to bypass security by spoofing the
Content-Type as image/jpeg. The uploaded file is stored in a predictable path within the uploadfile directory and can be executed directly by the web server. Real-world exploitation was first observed on 2024-11-03 (UTC).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Sea Cloud Ehr