Impact
The vulnerability in the procedure order AJAX deletion endpoint allows any authenticated user to delete procedure orders, answers, and specimens belonging to any patient, resulting in irreversible data loss. This affects the integrity of medical records and could compromise patient care.
Affected Systems
All installations of OpenEMR prior to version 8.0.0.3 are affected. The vulnerability is present in the OpenEMR application and is accessed through the local web interface.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, and the EPSS score of less than 1% suggests low current exploitation probability. The issue is not listed in the CISA KEV catalog. An attacker only needs to be authenticated to the system; no elevated privileges are required. The lack of authorization checks on the deletion endpoint provides a straightforward attack path to remove sensitive patient data and disrupt operations.
OpenCVE Enrichment