CVE-2023-38884

HIGH

openSIS Classic 9.0 - IDOR

Title source: llm
STIX 2.1

Description

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 57.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-639
Status published
Products (1)
os4ed/opensis 9.0
Published Nov 20, 2023
Tracked Since Feb 18, 2026