Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

Core staff sessions bypass patient boundaries in portal documents

GHSA-4r76-rq83-hgpg

Affected product
OpenEMR
Severity
Medium
Disclosed

Summary

OpenEMR's onsite-document APIs applied patient restrictions to portal sessions but not to ordinary staff sessions running in core mode. A low-privileged staff account could list, read, and modify other patients' portal document records. Affects versions before 8.4.0; fixed in 8.4.0.

Disclosure timeline

Public disclosure

Credits

Reported by christos-cantina-security; L0stHeart is also credited as a finder in OpenEMR's advisory.

References