PT-2020-12607 · Librehealthio · Librehealth Emr

Chris Davis

+1

·

Published

2020-07-15

·

Updated

2020-07-17

·

CVE-2020-11438

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibreHealth EMR version 2.0.0
Description The issue is related to systemic CSRF, which affects the software's ability to prevent cross-site request forgery attacks.
Recommendations For LibreHealth EMR version 2.0.0, consider implementing proper CSRF token validation to prevent unauthorized requests. As a temporary workaround, restrict access to sensitive functionality to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11438

Affected Products

Librehealth Emr