OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment records — including invoice/billing data (PHI) and payment card metadata — by manipulating the `recid` query parameter in `portal/portal_payment.php`. Version 8.0.0.3 patches the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Mar 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment records — including invoice/billing data (PHI) and payment card metadata — by manipulating the `recid` query parameter in `portal/portal_payment.php`. Version 8.0.0.3 patches the issue. | |
| Title | OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T23:36:48.165Z
Reserved: 2026-03-24T19:50:52.102Z
Link: CVE-2026-33931
No data.
Status : Received
Published: 2026-03-26T00:16:39.787
Modified: 2026-03-26T00:16:39.787
Link: CVE-2026-33931
No data.
OpenCVE Enrichment
No data.