Skip to content

One brick to the IT world

@manfromkz

  • Home
  • About
  • Contact

Tag: librehealth

Multiple vulnerabilities in LibreHealth EHR 2.0.0 part 2

During an internship at NitroTeam.kz, my students found several vulnerabilities in LibreHealth: Broken Access Control (CVE-2022-31496), Cross-Site Scripting (CVE-2022-31492, CVE-2022-31493, CVE-2022-31494, CVE-2022-31495, CVE-2022-31497, CVE-2022-31498).

Published June 2, 2022
Categorized as PHP, Research Tagged librehealth, open source, php, research, xss

Multiple vulnerabilities in LibreHealth EHR 2.0.0

I have found several vulnerabilities in open-source system LibreHealth EHR 2.0.0. More precisely 1 SQL-injection (CVE-2022-29938) and 2 Cross-site scripting (XSS) (CVE-2022-29939, CVE-2022-29940) vulnerabilities.

Published May 4, 2022
Categorized as PHP, Research Tagged cross-site script, librehealth, open source, OpenEMR, SQL-injection, xss, zero-day

Recent Posts

  • My speeches at OpenSysConf’22 and BeetechConf’23
  • SSRF vulnerability in the Tumbler plugin of XFCE
  • Interesting case with code execution in Nmap
  • Multiple vulnerabilities in LibreHealth EHR 2.0.0 part 2
  • Multiple vulnerabilities in LibreHealth EHR 2.0.0

Recent Comments

  • nomi on Review of PHP backdoors

Categories

  • CTF (2)
  • PHP (9)
  • Research (12)
  • Uncategorized (6)
One brick to the IT world
Proudly powered by WordPress.