CVE-2018-1000839: Librehealth Ehr

High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.

LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.

Affected products

Published 2018-12-20. Last modified 2026-06-17.