CVE-2018-1000650

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1000650
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000650.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000650
Published
2018-08-20T19:31:43Z
Modified
2024-05-14T06:16:03.126528Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.

References

Affected packages

Git / github.com/librehealthio/lh-ehr

Affected ranges

Type
GIT
Repo
https://github.com/librehealthio/lh-ehr
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

EventPlanning
INTERN
REL-1_0_0
REL-2_0_0
REL_100
REL_101
REL_1_0_1
v2_7_2
v2_7_2-rc1
v2_7_2-rc2
v2_7_3-rc1
v2_8_0
v2_8_1
v2_8_2
v2_8_3
v2_9_0
v3_0_0
v3_0_1