PT-2022-19923 · Unknown · Librehealth Emr
Manfromkz
·
Published
2022-05-05
·
Updated
2022-05-12
·
CVE-2022-29939
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LibreHealth EHR version 2.0.0
Description
The issue arises from the lack of sanitization of the GET parameters
debug and InsId in the interfacebillingsl eob process.php file, leading to multiple cross-site scripting (XSS) vulnerabilities.Recommendations
For LibreHealth EHR version 2.0.0, consider disabling access to the interfacebillingsl eob process.php file until a patch is available, or restrict the use of the
debug and InsId parameters to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librehealth Emr