### [CVE-2018-1000839](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000839) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type. ### POC #### Reference - https://0dd.zone/2018/09/03/lh-ehr-RCE-via-picture-upload/ - https://0dd.zone/2018/09/03/lh-ehr-RCE-via-picture-upload/ - https://github.com/LibreHealthIO/lh-ehr/issues/1223 - https://github.com/LibreHealthIO/lh-ehr/issues/1223 #### Github No PoCs found on GitHub currently.