CVE-2023-38885: CSRF
OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38885?
CVE-2023-38885 is a vulnerability in OpenSIS Classic Community Edition version 9.0 that lacks cross-site request forgery (CSRF) protection.
What is the severity of CVE-2023-38885?
The severity of CVE-2023-38885 is high, with a severity value of 8.8.
How does CVE-2023-38885 impact OpenSIS Classic Community Edition version 9.0?
CVE-2023-38885 allows an attacker to trick an authenticated user into performing any kind of state changing request.
How can I fix CVE-2023-38885 in OpenSIS Classic Community Edition version 9.0?
To fix CVE-2023-38885, it is recommended to implement proper cross-site request forgery (CSRF) protection throughout the whole app.
Where can I find more information about CVE-2023-38885?
For more information about CVE-2023-38885, you can refer to the following references: 1. GitHub repository: https://github.com/OS4ED/openSIS-Classic 2. OS4Ed website: https://www.os4ed.com/ 3. Vulnerability research repository: https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38885