Summary
A low-privileged OpenEMR staff account could move another patient's document into a readable category without document-management permission. Supplying an empty patient identifier then bypassed the ownership check when retrieving the file. The reported test demonstrated recategorization and download, not modification of the file contents. Affects versions before 8.3.0; fixed in 8.3.0.
Disclosure timeline
- Public disclosure
Credits
Reported by christos-cantina-security, as credited in OpenEMR's advisory.