Summary
OpenEMR's prescription API checked Medical/History access instead of prescription-management permissions. A staff account with read-only history access could list, create, and deactivate prescriptions for other patients. Affects versions before 8.4.0; fixed in 8.4.0.
Disclosure timeline
- Public disclosure
Credits
Reported by christos-cantina-security, as credited in OpenEMR's advisory.