7.5
CVSSv3

CVE-2023-38884

Published: 20/11/2023 Updated: 30/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote malicious user to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'

Vulnerable Product Search on Vulmon Subscribe to Product

os4ed opensis 9.0