Upwind Security MDR[verified]@UpwindMDRActive Exploitation
CVE‑2024‑14037 enables unauthenticated RCE via a file‑upload flaw in Red Sea Cloud eHR, with a public PoC and confirmed wild exploitation observed by Shadowserver; vendors advise restricting the affected endpoint.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The tweet announces CVE-2024-14037, highlighting a remote code execution flaw in Redsea Cloud eHR that allows arbitrary file uploads, and provides a link for further details.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces CVE-2024-14037, noting an arbitrary file upload flaw in Redsea Cloud eHR that can lead to unauthenticated remote code execution, without providing PoC, exploit code, or patch details.
CVE@CVEnewDisclosure
The post announces CVE-2024-14037, detailing an arbitrary file upload flaw that can lead to remote code execution, but offers no PoC, exploit code, or patch information.