First published: Mon Nov 20 2023(Updated: )
The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4ED openSIS-Classic | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38879 is a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php' in OS4ED's openSIS Classic version 9.0, which allows remote attackers to read arbitrary files.
CVE-2023-38879 has a severity score of 7.5 (high).
Remote attackers can exploit CVE-2023-38879 by manipulating the 'filename' parameter in 'DownloadWindow.php' to perform directory traversal attacks and read arbitrary files.
CVE-2023-38879 affects version 9.0 of OS4ED's openSIS Classic.
Currently, there is no known fix available for CVE-2023-38879. It is recommended to apply any patches or upgrades provided by the vendor when they become available.