


Perceptive Security
SOC/SIEM Consultancy

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious f…
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 18:03:40
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities
CVE-2024-14037 is a critical arbitrary file upload vulnerability in Redsea Cloud eHR that allows unauthenticated attackers to achieve remote code execution. Attackers exploit the PtFjk.mob servlet endpoint by submitting a multipart POST request containing a JSP webshell disguised with a spoofed image/jpeg Content-Type header. The vulnerability exists due to the absence of file extension and MIME type validation, enabling bypass of any upload restrictions. Uploaded malicious files are stored at a predictable path under the uploadfile directory and are directly executable by the web server. The flaw requires no authentication, significantly lowering the barrier for exploitation. Active exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-03 (UTC), indicating this vulnerability is being actively weaponized in the wild. The impact is severe as successful exploitation grants full remote code execution on the target server.
Technical details
Mitigation steps:
Affected products:
Redsea Cloud eHR
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2024-14037
https://cn-sec.com/archives/2734791.html
https://cn-sec.com/archives/3003231.html
https://redseacloud.com/
https://www.vulncheck.com/advisories/redsea-cloud-ehr-unauthenticated-file-upload-rce-via-ptfjk-mob
Related CVE's:
Related threat actors:
IOC's:
PtFjk.mob, /uploadfile/
This article was created with the assistance of AI technology by Perceptive.
