ZeroHour

CVE-2020-11436

PoC
CVSS 3.1
9.0 critical
EPSS
1%p70
Published
()
Modified
Description

LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.

Vendors
librehealth
Products
librehealth ehr
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.