📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2021-47758

High ⚡ Exploit Available
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Au
CWE-434 — Weakness Type
Published: Jan 15, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor that enables arbitrary command execution on the server through a weaponized PHP script.

🤖 AI Executive Summary

CVE-2021-47758 is a critical authenticated remote code execution vulnerability in Chikitsa Patient Management System 2.0.2 that allows attackers to upload malicious PHP plugins and execute arbitrary commands on healthcare servers. With CVSS 8.8 and publicly available exploits, this poses an immediate threat to healthcare organizations managing patient data. The vulnerability requires authentication but can be exploited by compromised internal accounts or through credential theft.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 22, 2026 01:58
🇸🇦 Saudi Arabia Impact Assessment
Healthcare sector organizations in Saudi Arabia using Chikitsa PMS 2.0.2 face critical risk to patient data confidentiality, integrity, and availability. Ministry of Health facilities, private hospitals, and clinics managing sensitive health records are primary targets. Compromised systems could lead to unauthorized access to patient medical histories, prescription data, and personal information, violating GDPR-equivalent healthcare privacy requirements. Potential impact extends to operational disruption of patient management workflows and regulatory compliance violations under Saudi healthcare data protection standards.
🏢 Affected Saudi Sectors
Healthcare Government Health Services Private Hospitals and Clinics Medical Research Institutions Pharmaceutical Distribution
⚖️ Saudi Risk Score (AI)
8.9
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all instances of Chikitsa PMS 2.0.2 in your healthcare environment
2. Restrict access to the module upload functionality to trusted administrators only
3. Review authentication logs for suspicious plugin uploads or failed authentication attempts
4. Isolate affected systems from production networks if exploitation is suspected

PATCHING:
1. Upgrade Chikitsa PMS to version 2.0.3 or later immediately
2. Verify patch application by checking version in system settings
3. Test functionality in staging environment before production deployment

COMPENSATING CONTROLS (if immediate patching not possible):
1. Disable plugin upload functionality at the application level
2. Implement Web Application Firewall (WAF) rules to block suspicious ZIP uploads to plugin endpoints
3. Restrict file upload permissions to read-only for PHP directories
4. Monitor /uploads and plugin directories for unauthorized PHP files

DETECTION:
1. Search for recently modified PHP files in plugin directories with timestamps after compromise window
2. Monitor for POST requests to plugin upload endpoints with ZIP file content-type
3. Alert on execution of PHP files in upload directories
4. Review web server logs for suspicious plugin activation patterns
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع نسخ Chikitsa PMS 2.0.2 في بيئة الرعاية الصحية الخاصة بك
2. تقييد الوصول إلى وظيفة تحميل الوحدات للمسؤولين الموثوقين فقط
3. مراجعة سجلات المصادقة للتحميلات المريبة أو محاولات المصادقة الفاشلة
4. عزل الأنظمة المتأثرة عن شبكات الإنتاج إذا كان الاستغلال مشبوهاً

التصحيح:
1. ترقية Chikitsa PMS إلى الإصدار 2.0.3 أو أحدث فوراً
2. التحقق من تطبيق التصحيح بفحص الإصدار في إعدادات النظام
3. اختبار الوظائف في بيئة التجريب قبل نشر الإنتاج

الضوابط البديلة (إذا لم يكن التصحيح الفوري ممكناً):
1. تعطيل وظيفة تحميل الملحقات على مستوى التطبيق
2. تنفيذ قواعد جدار حماية تطبيقات الويب لحظر تحميلات ZIP المريبة
3. تقييد أذونات تحميل الملفات للقراءة فقط لمجلدات PHP
4. مراقبة مجلدات التحميل والملحقات للملفات PHP غير المصرح بها

الكشف:
1. البحث عن ملفات PHP المعدلة مؤخراً في مجلدات الملحقات
2. مراقبة طلبات POST إلى نقاط نهاية تحميل الملحقات
3. التنبيه على تنفيذ ملفات PHP في مجلدات التحميل
4. مراجعة سجلات خادم الويب للأنماط المريبة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.2.1 - User endpoint devices ECC 2024 A.12.4.1 - Event logging
🔵 SAMA CSF
ID.BE-5 - Organizational resilience PR.DS-6 - Integrity checking mechanisms PR.IP-1 - Security patch management DE.CM-1 - The network is monitored for unauthorized connections
🟡 ISO 27001:2022
A.12.2.1 - Routine operations and change management A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy and procedures A.12.4.1 - Event logging
🟣 PCI DSS v4.0.1
Requirement 6.2 - Security patches must be installed Requirement 6.5.1 - Injection flaws prevention Requirement 11.2 - Vulnerability scanning
📦 Affected Products / CPE 1 entries
chikitsa:patient_management_system:2.0.2
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-434
EPSS0.57%
Exploit ✓ Yes
Patch ✓ Yes
Published 2026-01-15
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.9
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-434
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.