LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/LibreHealthIO/lh-ehr/issues/1223 | third party advisory exploit |
https://0dd.zone/2018/09/03/lh-ehr-RCE-via-picture-upload/ | third party advisory exploit |