VYPR

Librehealth Ehr

by LibreHealth

CVEs (22)

  • CVE-2022-29939MedMay 5, 2022
    risk 0.35cvss 5.4epss 0.01

    In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.

  • CVE-2020-11437MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.01

    LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database.

Page 2 of 2