CVE-2020-27408: High severity os4ed opensis-classic vulnerability
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27408?
The severity of CVE-2020-27408 is high with a CVSS score of 7.5.
How does CVE-2020-27408 affect OpenSIS Community Edition?
CVE-2020-27408 affects OpenSIS Community Edition through version 7.6.
What is the vulnerability description of CVE-2020-27408?
CVE-2020-27408 is an incorrect access control vulnerability in OpenSIS Community Edition that allows an unauthenticated attacker to change the password of arbitrary users.
How can an attacker exploit CVE-2020-27408?
An attacker can exploit CVE-2020-27408 by leveraging the incorrect access controls in the file ResetUserInfo.php to change the password of arbitrary users without authentication.
Are there any available fixes for CVE-2020-27408?
At the moment, there are no specific fixes available for CVE-2020-27408. It is recommended to follow the project's official releases and security advisories for any updates.