Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

REST document downloads can expose server-local files

GHSA-xgxv-36g2-hq5g

Affected product
OpenEMR
Severity
Medium
Disclosed

Summary

An authenticated OpenEMR user with document upload and download access could upload a file containing a server pathname. The REST download handler treated that content as a filesystem path and returned the referenced file, including database configuration in the reported test. Affects versions before 8.4.0; fixed in 8.4.0.

Disclosure timeline

Public disclosure

Credits

Cantina · Agent-discovered and human-verified

References