Impact
OpenEMR versions earlier than 8.3.0 contain a path traversal flaw in the EDI archive restore function. The archrestore_sel POST parameter is accepted without sanitizing directory traversal sequences, and the handler checks whether the supplied path exists on the file system. The difference between success or failure messages leaks whether the target file or directory exists. An authenticated user who has EOB Data Entry permissions can therefore probe arbitrary filesystem paths on the server and discover the presence of files and potentially sensitive directory structures. The vulnerability does not allow code execution or privilege escalation, but it enables enumeration of server files which could aid in subsequent attacks.
Affected Systems
The vendor is OpenEMR, and the product is the OpenEMR electronic medical record system. All releases prior to 8.3.0 are affected, as the fix was introduced in the 8.3.0 release.
Risk and Exploitability
The CVSS score of 5.3 rates this vulnerability as moderate. EPSS is < 1% and the issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with EOB Data Entry permissions; therefore the risk is limited to personnel with that role. Nonetheless, the ability to discover arbitrary files can assist attackers in building more targeted attacks against sensitive data stored on the system.
OpenCVE Enrichment