Security Advisory
CVE-2022-29939
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interfacebillingsl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.