Clinic's Patient Management System 1.0 - Unauthenticated RCE

cve CVE-2022-40471 1 source, 1 claim · Watch

Metasploit exploit modules writes:
This module exploits an unauthenticated file upload vulnerability in Clinic's Patient Management System 1.0. An attacker can upload a PHP web shell and execute it by leveraging directory listing enabled on the `/pms/user_images` directory. the claim

What each source says

PropertySourceSaidMeans here
Platform
platform
Metasploit exploit modulesPHP
receipt
Source
Metasploit exploit modules
Its words
PHP
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 14:23 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Aaryan Golatkar",
    "Oğulcan Hami Gül"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits an unauthenticated file upload vulnerability in Clinic's\n          Patient Management System 1.0. An attacker can upload a PHP web shell and execute\n          it by leveraging directory listing enabled on the `/pms/user_images` directory.",
  "disclosure_date": "2022-10-31",
  "fullname": "exploit/multi/http/clinic_pms_fileupload_rce",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:57:58 +0000",
  "name": "Clinic's Patient Management System 1.0 - Unauthenticated RCE",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/clinic_pms_fileupload_rce.rb",
  "platform": "PHP",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/clinic_pms_fileupload_rce",
  "references": [
    "EDB-51779",
    "CVE-2022-40471",
    "URL-https://www.cve.org/CVERecord?id=CVE-2022-40471",
    "URL-https://drive.google.com/file/d/1m-wTfOL5gY3huaSEM3YPSf98qIrkl-TW/view"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Clinic Patient Management System 1.0"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 14:23 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Aaryan Golatkar",
    "Oğulcan Hami Gül"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits an unauthenticated file upload vulnerability in Clinic's\n          Patient Management System 1.0. An attacker can upload a PHP web shell and execute\n          it by leveraging directory listing enabled on the `/pms/user_images` directory.",
  "disclosure_date": "2022-10-31",
  "fullname": "exploit/multi/http/clinic_pms_fileupload_rce",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:57:58 +0000",
  "name": "Clinic's Patient Management System 1.0 - Unauthenticated RCE",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/clinic_pms_fileupload_rce.rb",
  "platform": "PHP",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/clinic_pms_fileupload_rce",
  "references": [
    "EDB-51779",
    "CVE-2022-40471",
    "URL-https://www.cve.org/CVERecord?id=CVE-2022-40471",
    "URL-https://drive.google.com/file/d/1m-wTfOL5gY3huaSEM3YPSf98qIrkl-TW/view"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Clinic Patient Management System 1.0"
  ],
  "type": "exploit"
}
—

exploit

Clinic's Patient Management System 1.0 - Unauthenticated RCE
zetlyn/cve-metasploit · 2022-10-31
platform PHP rank 600 source