LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://0dd.zone/2018/08/07/lh-ehr-Authenticated-File-Write/ | third party advisory exploit |
https://github.com/LibreHealthIO/lh-ehr/issues/1211 | third party advisory exploit |