Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

Portal payment metadata permits cross-patient billing credits

GHSA-525m-fch5-vqqm

Affected product
OpenEMR
Severity
Medium
Disclosed

Summary

OpenEMR's Rainforest payment integration trusted patient and encounter amounts supplied by an authenticated portal user. The payment webhook could then record an inflated credit against another patient's bill without matching that credit to the amount actually paid. Affects versions before 8.4.0; fixed in 8.4.0.

Disclosure timeline

Public disclosure

Credits

Reported by christos-cantina-security, as credited in OpenEMR's advisory.

References