CVE-2018-1000646: Librehealth Ehr
High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
Affected products
- Librehealth Librehealth Ehr: version 2.0.0 only
Published 2018-08-20. Last modified 2026-06-17.