CVE-2023-38883: XSS
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38883?
CVE-2023-38883 is a reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic.
How does CVE-2023-38883 affect OS4ED OpenSIS Classic?
CVE-2023-38883 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.
What is the severity of CVE-2023-38883?
CVE-2023-38883 has a severity level of medium with a CVSS score of 6.1.
How can I fix CVE-2023-38883 in OS4ED OpenSIS Classic?
To fix CVE-2023-38883, it is recommended to update to a patched version of the Community Edition 9.0 of OS4ED's openSIS Classic. Ensure that you are using the latest version available.
Where can I find more information about CVE-2023-38883?
You can find more information about CVE-2023-38883 on the OS4ED website (https://www.os4ed.com/) and the OS4ED's openSIS Classic GitHub repository (https://github.com/OS4ED/openSIS-Classic).