remoteclinic CVE Vulnerabilities & Metrics

Focus on remoteclinic vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About remoteclinic Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with remoteclinic. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total remoteclinic CVEs: 13
Earliest CVE date: 13 Apr 2021, 00:15 UTC
Latest CVE date: 07 Nov 2023, 15:15 UTC

Latest CVE reference: CVE-2023-33481

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical remoteclinic CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.22

Max CVSS: 4.3

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 12
4.0-6.9 1
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS remoteclinic CVEs

These are the five CVEs with the highest CVSS scores for remoteclinic, sorted by severity first and recency.

All CVEs for remoteclinic

CVE-2023-33481 remoteclinic vulnerability CVSS: 0 07 Nov 2023, 15:15 UTC

RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.

CVE-2023-33480 remoteclinic vulnerability CVSS: 0 07 Nov 2023, 15:15 UTC

RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by a lack of input validation and access control in the staff/register.php endpoint and the edit-my-profile.php page. By sending a series of specially crafted requests to the RemoteClinic application, an attacker can create admin users with more privileges than their own, upload a PHP file containing arbitrary code, and execute arbitrary commands via the PHP shell.

CVE-2023-33479 remoteclinic vulnerability CVSS: 0 07 Nov 2023, 15:15 UTC

RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.

CVE-2023-33478 remoteclinic vulnerability CVSS: 0 07 Nov 2023, 15:15 UTC

RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.

CVE-2022-48152 remoteclinic vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parameter to /medicines/profile.php.

CVE-2021-39416 remoteclinic vulnerability CVSS: 4.3 05 Nov 2021, 16:15 UTC

Multiple Cross Site Scripting (XSS) vulnerabilities exists in Remote Clinic v2.0 in (1) patients/register-patient.php via the (a) Contact, (b) Email, (c) Weight, (d) Profession, (e) ref_contact, (f) address, (g) gender, (h) age, and (i) serial parameters; in (2) patients/edit-patient.php via the (a) Contact, (b) Email, (c) Weight, Profession, (d) ref_contact, (e) address, (f) serial, (g) age, and (h) gender parameters; in (3) staff/edit-my-profile.php via the (a) Title, (b) First Name, (c) Last Name, (d) Skype, and (e) Address parameters; and in (4) clinics/settings.php via the (a) portal_name, (b) guardian_short_name, (c) guardian_name, (d) opening_time, (e) closing_time, (f) access_level_5, (g) access_level_4, (h) access_level_ 3, (i) access_level_2, (j) access_level_1, (k) currency, (l) mobile_number, (m) address, (n) patient_contact, (o) patient_address, and (p) patient_email parameters.

CVE-2021-31329 remoteclinic vulnerability CVSS: 3.5 21 Apr 2021, 16:15 UTC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php

CVE-2021-31327 remoteclinic vulnerability CVSS: 3.5 21 Apr 2021, 16:15 UTC

Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.

CVE-2021-30044 remoteclinic vulnerability CVSS: 3.5 13 Apr 2021, 00:15 UTC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.

CVE-2021-30042 remoteclinic vulnerability CVSS: 3.5 13 Apr 2021, 00:15 UTC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register.php

CVE-2021-30039 remoteclinic vulnerability CVSS: 3.5 13 Apr 2021, 00:15 UTC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.

CVE-2021-30034 remoteclinic vulnerability CVSS: 3.5 13 Apr 2021, 00:15 UTC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.

CVE-2021-30030 remoteclinic vulnerability CVSS: 3.5 13 Apr 2021, 00:15 UTC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.