GHSA-c2ph-gr8x-j747MediumCVSS 4.3
OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The...
🔗 CVE IDs covered (1)
📋 Description
OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation against expected path formats. An attacker can craft a URL that causes an authenticated user with Patients - Documents permissions to make authenticated requests to arbitrary OpenEMR endpoints, enabling forced logout and other state-changing actions.
🔗 References (6)
- https://github.com/openemr/openemr/security/advisories/GHSA-wffp-pj5h-xqwp
- https://nvd.nist.gov/vuln/detail/CVE-2026-40509
- https://github.com/openemr/openemr/commit/f760adc7bddaf9d118e1a0d40590e686783ed21b
- https://github.com/openemr/openemr/releases/tag/v8_3_0
- https://www.vulncheck.com/advisories/openemr-csrf-via-dicom-viewer-web-path-parameter
- https://github.com/advisories/GHSA-c2ph-gr8x-j747