Summary
An authenticated low-privileged OpenEMR staff session could use its valid APICSRFTOKEN to enter the local FHIR API path without the expected authorization checks. The reported test retrieved questionnaire answers for multiple patients. Affects versions before 8.4.0; fixed in 8.4.0.
Disclosure timeline
- Public disclosure
Credits
Cantina · Agent-discovered and human-verified