ZeroHour

CVE-2023-38884

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
Description

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/ - '

Vendors
os4ed
Products
opensis
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.