CVE-2018-1000646: Librehealth Ehr

High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.

LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.

Affected products

Published 2018-08-20. Last modified 2026-06-17.