CVE-2023-38881: XSS
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into any of the 'calendarid', 'schooldate', 'month' or 'year' parameters in 'CalendarModal.php'.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38881?
CVE-2023-38881 is a reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic.
How does CVE-2023-38881 work?
CVE-2023-38881 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload into the 'calendar_id', 'school_date', 'month', or 'year' parameters.
What is the severity of CVE-2023-38881?
The severity of CVE-2023-38881 is medium with a CVSS score of 6.1.
How can I fix CVE-2023-38881?
To fix CVE-2023-38881, update to a patched version of OS4ED's openSIS Classic.
Where can I find more information about CVE-2023-38881?
You can find more information about CVE-2023-38881 on GitHub (https://github.com/OS4ED/openSIS-Classic) and the OS4ED website (https://www.os4ed.com/).