Klinika XP and KlinikaXP Insertino Hard-Coded Credentials Vulnerability

Vulnerability

A vulnerability exists in Klinika XP and KlinikaXP Insertino due to hard-coded credentials that allow unauthorized access to several internal services. This access includes the FTP server where the application's update packages are stored. With these credentials, an attacker could upload a malicious update file, which might then be distributed and installed on client machines as a legitimate update. This vulnerability affects Klinika XP versions prior to 5.39.01.01 and KlinikaXP Insertino versions prior to 3.1.0.1.

Impact

Exploitation of this vulnerability could lead to unauthorized access to internal services, including the FTP server hosting application update packages. This access could be used to upload malicious update files, potentially compromising client machines by installing the malicious files as legitimate updates.

Remediation

The hard-coded credentials have been removed from the code, and previously exposed credentials have been rotated to prevent further exploitation. Users are advised to update to Klinika XP version 5.39.09.49 or KlinikaXP Insertino version 3.1.0.1.

Added: Mar 23, 2026, 1:28 PM
Updated: Mar 23, 2026, 1:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.9
exploitability
4.5
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.