What's new
  • The default language of any content posted is English.
    Do not create multi-accounts, you will be blocked! For more information about rules, limits, and more, visit the Help page.
    Found a dead link? Use the report button!
On-Demand Doctor Appointment Booking SaaS Marketplace Business Model SaaSMonks

NULLED On-Demand Doctor Appointment Booking SaaS Marketplace Business Model SaaSMonks 9.3.0 NULLED

raz0r 's signature
Reacted by:
  • Like
Reactions: emyhunk and Serg
raz0r updated On-Demand Doctor Appointment Booking SaaS Marketplace Business Model SaaSMonks with a new update entry:

Doctro 9.2.0 NULLED

v9.2.0 Update 12-APR-2025
– [ADD] add default dialing code configuration
– [ENHANCEMENT] Improve OneSignal notification error handling and device token checks
– [ENHANCEMENT] Roles & Permissions
– [ENHANCEMENT] Add dynamic title support in main layout and update doctor detail view
– [FIX] Add cache reset after role creation
– [FIX] removed section in role management view to prevent accidentally mixing roles and permissions
– [FIX] Added missed import for OneSignal
– [FIX] booking...

Read the rest of this update entry...
 
raz0r 's signature
Reacted by:
  • Like
Reactions: Serg
Thanks for this. Please, do you have the Doctor Appointment Booking & Medicine Ordering Flutter App v7.3.1
 
Reacted by:
Sorry to disturb again. They just released the 9.3.0, and I was wondering if you have it?
 
Reacted by:
raz0r updated On-Demand Doctor Appointment Booking SaaS Marketplace Business Model SaaSMonks with a new update entry:

Doctro 9.3.0 NULLED

v9.3.0 Update 09-MAY-2025
[ADD] patient details pre-filled in appointment booking form
[FIX] Verification routing issues
[FIX] added Chat notification APIs
[FIX] Update OneSignal notification handling for improved error logging and code clarity
[FIX] Refactor distance query in Hospital, Lab and Pharmacy models for improved security and readability

Read the rest of this update entry...
 
raz0r 's signature
Reacted by:
  • Like
Reactions: emyhunk and Serg
Thanks so much for this
I found Remote Code Execution (RCE) or Code Execution or Code Injection or Command Injection enables the attacker to inject and execute malicious code by passing an arbitrary command to the remote system. at the file of

doctro-9.3.0\doctro_admin_website\vendor\dompdf\dompdf\src\Adapter\CPDF.php
doctro-9.3.0\doctro_admin_website\vendor\dompdf\dompdf\src\Adapter\PDFLib.php
doctro-9.3.0\doctro_admin_website\vendor\dompdf\dompdf\src\PhpEvaluator.php
doctro-9.3.0\doctro_admin_website\vendor\psy\psysh\src\Command\EditCommand.php
doctro-9.3.0\doctro_admin_website\vendor\symfony\console\Command\DumpCompletionCommand.php

Code:
79.<comment>Dynamic installation
80.--------------------</>
81.
82.Add this to the end of your shell configuration file (e.g. <info>"{$rcFile}"</>):
83.
84. <info>eval "$({$fullCommand} completion {$shell})"</>
85.EOH
86. )
87. ->addArgument('shell', InputArgument::OPTIONAL, 'The shell type (e.g. "bash"), the value of the "$SHELL" env var will be used if this is not given', null, $this->getSupportedShells(...))
88. ->addOption('debug', null, InputOption::VALUE_NONE, 'Tail the completion debug log')
[/QUOTE]
Tested by 0x01 Nullcave Security Auditor
[QUOTE]


@raz0r The attacker can upload a Shell to the web server.
 
Last edited:
Reacted by:
  • Like
Reactions: tisna
Top