First published: Mon Nov 20 2023(Updated: )
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38884 is an Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic.
CVE-2023-38884 allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'.
CVE-2023-38884 has a severity of 7.5 (high).
To fix the Insecure Direct Object Reference (IDOR) vulnerability in openSIS Classic version 9.0, it is recommended to apply the latest security patches or updates provided by OS4Ed.
More information about CVE-2023-38884 can be found at the following references: [GitHub repository](https://github.com/OS4ED/openSIS-Classic), [OS4Ed website](https://www.os4ed.com/), [Vulnerability research](https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38884).