CVE-2018-1000839: Librehealth Ehr
High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
Affected products
- Librehealth Librehealth Ehr: version 2.0.0 only
Published 2018-12-20. Last modified 2026-06-17.