Summary
An authenticated OpenEMR patient could override the onsite-document API's patient and locked-document filters with empty values. This removed the intended restrictions and exposed other patients' consent artifacts, including document content and signatures. Affects versions before 8.3.0; fixed in 8.3.0.
Disclosure timeline
- Public disclosure
Credits
Reported by christos-cantina-security, as credited in OpenEMR's advisory.