cve/2020/CVE-2020-23829.md
2024-06-09 00:33:16 +00:00

770 B

CVE-2020-23829

Description

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

POC

Reference

Github