Librehealth
librehealth
22 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (22)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Jun 8, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Jun 7, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Jun 6, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Jun 6, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Jun 6, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Jun 6, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS. |
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities. |
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities. |
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection. |
interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uplo...Show more |
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application. |
LibreHealth EMR v2.0.0 is affected by systemic CSRF. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Jul 15, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Jul 15, 2020 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators. |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME ty...Show more |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Aug 20, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitabl...Show more |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Aug 20, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead...Show more |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Aug 20, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code exe...Show more |
1Librehealth 1Librehealth Ehr Nov 21, 2024 Aug 20, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled p...Show more |