The csvloghtml function in library/edihistory/edihcsvinc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.