CVE-2018-10572
interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters.
Date published : 2018-04-30
https://github.com/openemr/openemr/commit/699e3c2ef68545357cac714505df1419b8bf2051