Lucene search

K
osvGoogleOSV:CVE-2020-23829
HistorySep 01, 2020 - 5:15 p.m.

CVE-2020-23829

2020-09-0117:15:11
Google
osv.dev
3
cve-2020-23829
webserver
remote code execution
file upload
librehealth ehr 2.0.0
authenticated vulnerability

AI Score

7.7

Confidence

High

EPSS

0.012

Percentile

85.3%

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

AI Score

7.7

Confidence

High

EPSS

0.012

Percentile

85.3%

Related for OSV:CVE-2020-23829