Show plain JSON{"id": "CVE-2018-1000647", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.1, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "NONE"}, "impactScore": 4.2, "exploitabilityScore": 2.8}]}, "published": "2018-08-20T19:31:41.683", "references": [{"url": "https://0dd.zone/2018/08/07/lh-ehr-Authenticated-File-Deletion/", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://github.com/LibreHealthIO/lh-ehr/issues/1212", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://0dd.zone/2018/08/07/lh-ehr-Authenticated-File-Deletion/", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://github.com/LibreHealthIO/lh-ehr/issues/1212", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-20"}, {"lang": "en", "value": "CWE-22"}]}], "descriptions": [{"lang": "en", "value": "LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter."}, {"lang": "es", "value": "LibreHealthIO lh-ehr en versiones anteriores a REL-2.0.0 contiene una vulnerabilidad de borrado de archivos autenticados sin restricciones en la plantilla Import que puede resultar en una denegaci\u00f3n de servicio (DoS). Parece ser que este ataque puede ser explotado mediante un par\u00e1metro controlado por el usuario."}], "lastModified": "2024-11-21T03:40:19.130", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:librehealth:librehealth_ehr:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E9170AF-92DB-4B39-AC8F-73EB8CB496CC"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}