LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-12-20T15:00:00Z

Updated: 2024-09-16T17:07:49.030Z

Reserved: 2018-12-20T00:00:00Z

Link: CVE-2018-1000839

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-12-20T15:29:01.813

Modified: 2019-02-01T20:26:47.397

Link: CVE-2018-1000839

cve-icon Redhat

No data.