Impact
An insecure direct object reference in the patient portal payment page allows authenticated patients to view payment records that belong to other patients by manipulating the recid query parameter. This enables exposure of billing information and payment card metadata, compromising confidentiality of protected health information and potentially enabling financial fraud.
Affected Systems
OpenEMR, version 8.0.0.2 and earlier, is affected. The vulnerability is in the patient portal payment page of the OpenEMR application.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity while an EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack requires only that an attacker has an authenticated patient account; no additional credentials or administrative access are necessary, making the attack surface broad for all users of the affected versions.
OpenCVE Enrichment