Librehealth
Librehealth EHR: vulnerabilidades y CVE
Librehealth EHR tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-31496 | Alta (8.8) | 2.0% | — | 9 jun 2022 | LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. |
| CVE-2022-31497 | Media (6.1) | 0.90% | — | 8 jun 2022 | LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS. |
| CVE-2022-31495 | Media (6.1) | 0.97% | — | 7 jun 2022 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS. |
| CVE-2022-31494 | Media (6.1) | 1.0% | — | 6 jun 2022 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS. |
| CVE-2022-31498 | Media (6.1) | 0.97% | — | 6 jun 2022 | LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS. |
| CVE-2022-31492 | Media (6.1) | 0.97% | — | 6 jun 2022 | Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username. |
| CVE-2022-31493 | Media (6.1) | 0.97% | — | 6 jun 2022 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS. |
| CVE-2022-29940 | Media (5.4) | 0.87% | — | 5 may 2022 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities. |
| CVE-2022-29939 | Media (5.4) | 0.87% | — | 5 may 2022 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities. |
| CVE-2022-29938 | Alta (8.8) | 1.5% | — | 5 may 2022 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection. |
| CVE-2020-23829 | Alta (8.8) | 2.5% | — | 1 sept 2020 | interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by… |
| CVE-2020-11439 | Alta (8.8) | 2.0% | — | 15 jul 2020 | LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application. |
| CVE-2020-11438 | Alta (8.8) | 0.64% | — | 15 jul 2020 | LibreHealth EMR v2.0.0 is affected by systemic CSRF. |
| CVE-2020-11437 | Media (4.3) | 0.95% | — | 15 jul 2020 | LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database. |
| CVE-2020-11436 | Crítica (9) | 1.3% | — | 15 jul 2020 | LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators. |
| CVE-2018-1000839 | Alta (8.8) | 3.1% | — | 20 dic 2018 | LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME… |
| CVE-2018-1000650 | Alta (8.8) | 1.5% | — | 20 ago 2018 | LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be… |
| CVE-2018-1000649 | Alta (8.8) | 2.8% | — | 20 ago 2018 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead… |
| CVE-2018-1000648 | Alta (8.8) | 2.8% | — | 20 ago 2018 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code… |
| CVE-2018-1000647 | Alta (7.1) | 1.5% | — | 20 ago 2018 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled… |
| CVE-2018-1000646 | Alta (8.8) | 3.3% | — | 20 ago 2018 | LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution. |
| CVE-2018-1000645 | Media (6.5) | 1.4% | — | 20 ago 2018 | LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the… |