Vulnerabilities > Librehealth

DATE CVE VULNERABILITY TITLE RISK
2018-08-20 CVE-2018-1000646 Unrestricted Upload of File with Dangerous Type vulnerability in Librehealth EHR 2.0.0
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
network
low complexity
librehealth CWE-434
8.8
2018-08-20 CVE-2018-1000645 Information Exposure vulnerability in Librehealth EHR 1.0.0/1.0.1
LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server.
network
low complexity
librehealth CWE-200
6.5