Impact
OpenEMR before 8.3.0 contains a CSRF flaw in the DICOM viewer. The web_path GET parameter is embedded as a URL without validation, allowing an attacker to craft a link that forces an authenticated user with Patients‑Documents permissions to make arbitrary requests to OpenEMR endpoints, such as forced logout or other state‑changing actions.
Affected Systems
All installations of OpenEMR that use a version earlier than 8.3.0 and expose the DICOM viewer functionality are affected. Users granted the Patients‑Documents role are the primary targets.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity. The EPSS score is not available, so the probability of exploitation is uncertain, but the attack requires a victim to visit a malicious URL in a browser. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation at this time. The likely attack vector is an authenticated user’s browser session that receives a crafted link from an attacker.
OpenCVE Enrichment