4mosan develops GCB Doctor, a specialized medical or diagnostic software product with a narrow vendor footprint. Its vulnerability profile centers on authentication and authorization lapses alongside insecure file-upload handling, reflecting the access-control and data-handling demands of healthcare or clinical applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 4mosan over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44159CRITICAL 4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execu | Dec 20, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-42338CRITICAL 4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrar | Nov 19, 2021 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 4mosan.
Media articles that mention a CVE ID that affects a product developed by 4mosan — matched by CVE ID, not by vendor name.