Vulnerabilities > CVE-2023-38884 - Authorization Bypass Through User-Controlled Key vulnerability in Os4Ed Opensis 9.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
os4ed
CWE-639

Summary

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'

Vulnerable Configurations

Part Description Count
Application
Os4Ed
1