LibreHealthIO/lh-ehr

LibreHealthIO/lh-ehr

Releases29
Frequency6 months 4 weeks
Last Release
Stars296
LibreHealth EHR - Free Open Source Electronic Health Records

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH9 HIGH

LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.

6.1 MEDIUM4.3 MEDIUM

LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.

6.1 MEDIUM4.3 MEDIUM

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.

6.1 MEDIUM4.3 MEDIUM

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.

6.1 MEDIUM4.3 MEDIUM

LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.

6.1 MEDIUM4.3 MEDIUM

Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.

6.1 MEDIUM4.3 MEDIUM

LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.

5.4 MEDIUM3.5 LOW

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.

5.4 MEDIUM3.5 LOW

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.

8.8 HIGH6.5 MEDIUM

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.

6.5 MEDIUM

LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.

6.5 MEDIUM

LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.

6.5 MEDIUM

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled input.

6.5 MEDIUM

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.

5.5 MEDIUM

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.

6.5 MEDIUM

LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.

4 MEDIUM

LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function.