ZeroHour

CVE-2023-38885

CVSS 3.1
8.8 high
EPSS
<1%p30
Published
()
Modified
Description

OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.

Vendors
os4ed
Products
opensis
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.