CVE-2023-38879: Path Traversal
The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38879?
CVE-2023-38879 is a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php' in OS4ED's openSIS Classic version 9.0, which allows remote attackers to read arbitrary files.
What is the severity of CVE-2023-38879?
CVE-2023-38879 has a severity score of 7.5 (high).
How can remote attackers exploit CVE-2023-38879?
Remote attackers can exploit CVE-2023-38879 by manipulating the 'filename' parameter in 'DownloadWindow.php' to perform directory traversal attacks and read arbitrary files.
Which version of openSIS Classic is affected by CVE-2023-38879?
CVE-2023-38879 affects version 9.0 of OS4ED's openSIS Classic.
Is there a fix available for CVE-2023-38879?
Currently, there is no known fix available for CVE-2023-38879. It is recommended to apply any patches or upgrades provided by the vendor when they become available.