NA

CVE-2023-38885

Published: 20/11/2023 Updated: 30/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an malicious user to trick an authenticated user into performing any kind of state changing request.

Vulnerable Product Search on Vulmon Subscribe to Product

os4ed opensis 9.0