PT-2026-24841 · Git+1 · Openemr
Pavelkohout396
·
Publicado
2026-03-11
·
Atualizado
2026-03-11
·
CVE-2026-32122
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.0.0.1
Description
OpenEMR is an electronic health records and medical practice management application. The Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata, including claim IDs, payer information, and transmission logs. This endpoint does not enforce the same Access Control List (ACL) as the main billing/claims workflow, allowing authenticated users without appropriate billing permissions to access sensitive data. The vulnerable API endpoint is an AJAX endpoint used by the Claim File Tracker feature. The issue arises because the endpoint does not properly validate user permissions before returning billing claim metadata. The vulnerable parameter is not explicitly mentioned.
Recommendations
Update OpenEMR to version 8.0.0.1 or later.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openemr