Security Advisory

CVE-2018-1000839

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-12-20 15:00:00
Last updated 2024-09-16 17:07:49
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.