Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Librehealth Subscribe
Filtered by product Librehealth Ehr
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1000646 1 Librehealth 1 Librehealth Ehr 2018-10-16 6.5 MEDIUM 8.8 HIGH
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
CVE-2018-1000645 1 Librehealth 1 Librehealth Ehr 2018-10-16 4.0 MEDIUM 6.5 MEDIUM
LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function.