Vulnerabilities (CVE)

Filtered by vendor Librehealth Subscribe
Filtered by product Librehealth Ehr
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1000650 1 Librehealth 1 Librehealth Ehr 2024-02-04 6.5 MEDIUM 8.8 HIGH
LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.
CVE-2018-1000646 1 Librehealth 1 Librehealth Ehr 2024-02-04 6.5 MEDIUM 8.8 HIGH
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.