Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

Empty portal filters expose other patients' locked consent documents

GHSA-v688-m84c-5h4v

Affected product
OpenEMR
Severity
High
Disclosed

Summary

An authenticated OpenEMR patient could override the onsite-document API's patient and locked-document filters with empty values. This removed the intended restrictions and exposed other patients' consent artifacts, including document content and signatures. Affects versions before 8.3.0; fixed in 8.3.0.

Disclosure timeline

Public disclosure

Credits

Reported by christos-cantina-security, as credited in OpenEMR's advisory.

References