Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-40471 — Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471 | Kitploit
Tools/GitHubGitHub/dharan10/cve-2022-40471
Payload GenerationVulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubdharan10/cve-2022-40471

CVE-2022-40471

Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471

View Repository
99 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-40471 – CPMS Authenticated File Upload RCE

📌 Overview

CVE-2022-40471 is an authenticated Remote Code Execution vulnerability affecting
Clinic's Patient Management System (CPMS).

The vulnerability exists due to insufficient validation of uploaded files in the user profile image upload functionality, allowing an authenticated attacker to upload and execute arbitrary PHP code.


🧠 Vulnerability Details

  • Product: Clinic's Patient Management System (CPMS)
  • Vulnerability Type: Authenticated File Upload → Remote Code Execution
  • CVE ID: CVE-2022-40471
  • Attack Vector: Web
  • Authentication Required: Yes
  • Impact: Full remote command execution

⚙️ Exploitation Flow

  1. Authenticate using valid CPMS credentials
  2. Upload a malicious PHP file via the profile image upload feature
  3. Access the uploaded PHP shell to execute OS commands

🚀 Usage

Requirements

  • Python 3.x
  • requests library
pip install requests
Download Tool