Librehealth

Librehealth Ehr

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.47%
  • Veröffentlicht 01.09.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:14:06

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted im...

Exploit
  • EPSS 0.76%
  • Veröffentlicht 15.07.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:57:55

LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 15.07.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:57:55

LibreHealth EMR v2.0.0 is affected by systemic CSRF.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 15.07.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:57:54

LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database.

Exploit
  • EPSS 0.74%
  • Veröffentlicht 15.07.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:57:54

LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.

Exploit
  • EPSS 3.84%
  • Veröffentlicht 20.12.2018 15:29:01
  • Zuletzt bearbeitet 21.11.2024 03:40:28

LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 20.08.2018 19:31:43
  • Zuletzt bearbeitet 21.11.2024 03:40:19

LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled paramete...

Exploit
  • EPSS 1.99%
  • Veröffentlicht 20.08.2018 19:31:43
  • Zuletzt bearbeitet 21.11.2024 03:40:19

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This...

Exploit
  • EPSS 1.99%
  • Veröffentlicht 20.08.2018 19:31:42
  • Zuletzt bearbeitet 21.11.2024 03:40:19

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to ...

Exploit
  • EPSS 0.95%
  • Veröffentlicht 20.08.2018 19:31:41
  • Zuletzt bearbeitet 21.11.2024 03:40:19

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.