Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2022-29939
Disclosure Date: May 05, 2022 (last updated February 23, 2025)
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.
0
Attacker Value
Unknown
CVE-2022-29938
Disclosure Date: May 05, 2022 (last updated February 23, 2025)
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.
0
Attacker Value
Unknown
CVE-2020-23829
Disclosure Date: September 01, 2020 (last updated February 22, 2025)
interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.
0
Attacker Value
Unknown
CVE-2020-11439
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.
0
Attacker Value
Unknown
CVE-2020-11436
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.
0
Attacker Value
Unknown
CVE-2020-11438
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
LibreHealth EMR v2.0.0 is affected by systemic CSRF.
0
Attacker Value
Unknown
CVE-2020-11437
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database.
0
Attacker Value
Unknown
CVE-2018-1000839
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
0
Attacker Value
Unknown
CVE-2018-1000650
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.
0
Attacker Value
Unknown
CVE-2018-1000646
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
0