LH-EHR version REL-200 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-1000839.json"