Summary
OpenEMR's onsite-document APIs applied patient restrictions to portal sessions but not to ordinary staff sessions running in core mode. A low-privileged staff account could list, read, and modify other patients' portal document records. Affects versions before 8.4.0; fixed in 8.4.0.
Disclosure timeline
- Public disclosure
Credits
Reported by christos-cantina-security; L0stHeart is also credited as a finder in OpenEMR's advisory.