Chikitsa
Products
3- 5 CVEs
- 2 CVEs
- 2 CVEs
Recent CVEs
7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-47758 | Hig | 0.57 | 8.8 | 0.01 | Jan 15, 2026 | Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor… | ||
| CVE-2021-47757 | Hig | 0.57 | 8.8 | 0.01 | Jan 15, 2026 | Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the… | ||
| CVE-2021-38152 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2021 | index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS. | ||
| CVE-2021-38151 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2021 | index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS. | ||
| CVE-2021-38149 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2021 | index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS. | ||
| CVE-2021-42869 | Med | 0.31 | 4.8 | 0.01 | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages. | ||
| CVE-2021-42868 | Med | 0.31 | 4.8 | 0.01 | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. . |
- risk 0.57cvss 8.8epss 0.01
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor…
- risk 0.57cvss 8.8epss 0.01
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the…
- risk 0.35cvss 5.4epss 0.01
index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.
- risk 0.35cvss 5.4epss 0.01
index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
- risk 0.35cvss 5.4epss 0.01
index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.
- risk 0.31cvss 4.8epss 0.01
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.
- risk 0.31cvss 4.8epss 0.01
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. .