First published: Fri Dec 04 2020(Updated: )
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4ED openSIS-Classic | <=7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-27408 is high with a CVSS score of 7.5.
CVE-2020-27408 affects OpenSIS Community Edition through version 7.6.
CVE-2020-27408 is an incorrect access control vulnerability in OpenSIS Community Edition that allows an unauthenticated attacker to change the password of arbitrary users.
An attacker can exploit CVE-2020-27408 by leveraging the incorrect access controls in the file ResetUserInfo.php to change the password of arbitrary users without authentication.
At the moment, there are no specific fixes available for CVE-2020-27408. It is recommended to follow the project's official releases and security advisories for any updates.