← volver
CVE-2026-33931

OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access

CVSS 6.5 MEDIUMEPSS 0.4%CWE-639
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
25 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment records — including invoice/billing data (PHI) and payment card metadata — by manipulating the `recid` query parameter in `portal/portal_payment.php`. Version 8.0.0.3 patches the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Productos afectados
openemr · openemr

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →