CVE-2024-14037Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with a JSP webshell disguised using a spoofed image/jpeg Content-Type to bypass the absence of extension and MIME type validation, with the uploaded file stored at a predictable path under the uploadfile directory and executed directly by the web server. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-03 (UTC).

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-02); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-02: 2Mentions · 2026-07-03: 1Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-07-03: 1Active Exploitation · 2026-07-03: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 1Technical Details · 2026-07-13: 107-0207-0307-13
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-022
Disclosure2
2026-07-031
Active Exploitation1
2026-07-131
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2024-14037 Remote Code Execution via Arbitrary File Upload in Redsea Cloud eHR https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-14037

    Post summary

    The tweet announces CVE-2024-14037, highlighting a remote code execution flaw in Redsea Cloud eHR that allows arbitrary file uploads, and provides a link for further details.

    00000125
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Active Exploitation

    🚨Critical - Red Sea Cloud eHR Unauthenticated File Upload RCE (CVE-2024-14037) Red Sea Cloud eHR's PtFjk.mob servlet accepts multipart uploads with no extension or MIME type validation. An unauthenticated attacker can submit a JSP webshell disguised with a spoofed image/jpeg Content-Type; the file is stored at a predictable path under the uploadfile directory and executed directly by the web server. The result is unauthenticated remote code execution. CISA rates it as automatable with a public PoC, and exploitation has been observed in the wild by Shadowserver since November 2024. 👉Affected: all Red Sea Cloud eHR versions - apply vendor guidance / restrict access to the PtFjk.Mob endpoint.

    Post summary

    CVE‑2024‑14037 enables unauthenticated RCE via a file‑upload flaw in Red Sea Cloud eHR, with a public PoC and confirmed wild exploitation observed by Shadowserver; vendors advise restricting the affected endpoint.

    00000133
    236 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2024-14037 Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files t… https://www.cve.org/CVERecord?id=CVE-2024-14037 ----- Traducción: CVE-2024-14037 Red… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2024-14037, noting an arbitrary file upload flaw in Redsea Cloud eHR that can lead to unauthenticated remote code execution, without providing PoC, exploit code, or patch details.

    0000033
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2024-14037 Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files t… https://www.cve.org/CVERecord?id=CVE-2024-14037

    Post summary

    The post announces CVE-2024-14037, detailing an arbitrary file upload flaw that can lead to remote code execution, but offers no PoC, exploit code, or patch information.

    00000758
    57.7K followersView on X

Explore more