Product GitHub Repositoryproduct
https://github.com/sanskruti-technologies/chikitsa CVE-2021-47758
HIGH
Chikitsa Patient Management System 2.0.2 - Remote Code Execution (RCE) (Authenticated)
Record summary
CVE-2021-47758 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor that enables arbitrary command execution on the server through a weaponized PHP script.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Chikitsa Patient Management SystemBrowse dharashah / Chikitsa Patient Management System | CVE List | 2.0.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBChikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby 0z09eNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47758 Product Sourceforge Pageproduct
https://sourceforge.net/projects/chikitsa Product Webpageproduct
https://www.chikitsa.io/ ExploitDB-50571exploit
https://www.exploit-db.com/exploits/50571