Impact
Medical Practice Management System is vulnerable to Remote Code Execution. An unauthenticated attacker can trigger arbitrary operating‑system commands by delivering a specially crafted HTML page to the vulnerable application. This weakness allows the attacker to compromise confidentiality, integrity, and availability of the affected system without any credentials.
Affected Systems
The vulnerability affects Le‑yan Medical Practice Management System. All releases prior to 2.5.2.0 are impacted; the vendor recommends upgrading to version 2.5.2.0 or later to receive the fix.
Risk and Exploitability
The CVSS score of 8.6 indicates a high‑severity flaw. EPSS is not available, and the vulnerability is not listed in CISA KEV, but the lack of authentication requirement and the ability to execute arbitrary commands imply a high likelihood of exploitation for network‑reachable installations. The likely attack vector is remote via the web interface, meaning any system exposed to untrusted traffic is at risk.
OpenCVE Enrichment