BinSoft mpGabinet是波兰BinSoft公司的一个医疗诊所管理系统。 BinSoft mpGabinet 23.12.19及之前版本存在安全漏洞,该漏洞源于远程命令执行问题,可能导致授权用户通过上传附件并修改数据库中存储路径为攻击者控制的远程网络资源,或更改已有文件引用,当用户尝试打开附件时系统执行引用资源,未授权攻击者可通过与CVE-2026-40550和CVE-2026-40551链式利用获取数据库访问权限并登录任意账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BinSoft | mpCRM | ≤ 25.2.4 |
affected |
| BinSoft | mpFaktura | ≤ 26.4.9 |
affected |
| BinSoft | mpFirma | ≤ 26.4.9 |
affected |
| BinSoft | mpFirma ERP | ≤ 26.4.9 |
affected |
| BinSoft | mpGabinet | ≤ 23.12.19 |
affected |
| BinSoft | mpPOS | ≤ 25.2.4 |
affected |
| BinSoft | mpSekretariat | ≤ 25.2.4 |
affected |
| BinSoft | mpWarsztat | ≤ 20.4.28 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40551 | 8.4 HIGH | Use of Client-Side Authentication in multiple BinSoft products |
| CVE-2026-40550 | 6.9 MEDIUM | Privilege Escalation in multiple BinSoft products |
No comments yet