Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

Local-session API authorization exposes patient questionnaire answers

GHSA-5xf2-3h9x-f4m6

Affected product
OpenEMR
Severity
Medium
Disclosed

Summary

An authenticated low-privileged OpenEMR staff session could use its valid APICSRFTOKEN to enter the local FHIR API path without the expected authorization checks. The reported test retrieved questionnaire answers for multiple patients. Affects versions before 8.4.0; fixed in 8.4.0.

Disclosure timeline

Public disclosure

Credits

Cantina · Agent-discovered and human-verified

References