{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T06:11:16.543","vulnerabilities":[{"cve":{"id":"CVE-2026-25147","sourceIdentifier":"security-advisories@github.com","published":"2026-02-27T17:16:30.933","lastModified":"2026-06-17T10:24:11.420","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $pid` and `$pid = ($_REQUEST['hidden_patient_code'] ?? null) > 0 ? $_REQUEST['hidden_patient_code'] : $pid`) instead of being fixed to the authenticated portal user. The portal session already has a valid `$pid` for the logged-in patient. Overwriting it with user-supplied values and using it without authorization allows a portal user to view and interact with another patient's demographics, invoices, and payment history—horizontal privilege escalation and IDOR. Version 8.0.0 contains a fix for the issue."},{"lang":"es","value":"OpenEMR es una aplicación de gestión de registros médicos electrónicos y práctica médica de código abierto y gratuita. Antes de la versión 8.0.0, en 'portal/portal_payment.php', el ID de paciente utilizado para la página se toma de la solicitud ('$pid = $_REQUEST['pid'] ?? $pid' y '$pid = ($_REQUEST['hidden_patient_code'] ?? null) &gt; 0 ? $_REQUEST['hidden_patient_code'] : $pid') en lugar de estar fijo al usuario autenticado del portal. La sesión del portal ya tiene un '$pid' válido para el paciente que ha iniciado sesión. Sobrescribirlo con valores proporcionados por el usuario y usarlo sin autorización permite a un usuario del portal ver e interactuar con los datos demográficos, facturas e historial de pagos de otro paciente —escalada de privilegios horizontal e IDOR. La versión 8.0.0 contiene una solución para el problema."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"openemr","product":"openemr","versions":[{"version":"< 8.0.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-27T18:27:48.774045Z","id":"CVE-2026-25147","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0.0","matchCriteriaId":"FEAA9896-A42E-437C-BEE8-8DA955E34385"}]}]}],"references":[{"url":"https://github.com/openemr/openemr/commit/d6ab3cd0b621b19b942cf49d2db2026e288aa214","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/openemr/openemr/security/advisories/GHSA-mwmw-qxv3-8whh","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]}]}}]}