Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

C-Stoop

#31715de 56,330
8.8CVSS total
Vulnerabilidades · 1
PT-2018-9563
8.8
2018-12-20
Lh · Lh-Ehr · CVE-2018-1000839
**Name of the Vulnerable Software and Affected Versions** LH-EHR version REL-2 0 0 **Description** The issue concerns an Arbitrary File Upload vulnerability in the Profile picture upload feature, which can lead to Remote Code Execution. This can be exploited by uploading a PHP file with an image MIME type. **Recommendations** For LH-EHR version REL-2 0 0, consider disabling the Profile picture upload feature until a patch is available to prevent exploitation. Restrict access to the upload functionality to minimize the risk of Remote Code Execution. Avoid using the Profile picture upload feature with unvalidated user input until the issue is resolved.