PT-2026-78480 · Openemr · Openemr
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.3.0
Description
A path traversal issue exists in the EDI archive restore function. The
archrestore sel POST parameter is processed by the archive restore handler without proper sanitization for path traversal sequences. This allows an authenticated user with EOB Data Entry permissions to probe arbitrary filesystem paths on the server. The system leaks information about the existence of target files through differing response messages.Recommendations
Update to version 8.3.0 or later.
Restrict the use of the
archrestore sel parameter in the EDI archive restore function until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr