CVE-2018-1000839
20.12.2018, 15:29
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.Enginsight
Vendor | Product | Version |
---|---|---|
librehealth | librehealth_ehr | 2.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration