CVE-2018-1000650

Publication date

2018-08-20 19:00:00

Family

mitre

State

PUBLISHED

Description

LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.