Security Advisory

CVE-2023-38884

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-11-20 00:00:00
Last updated 2024-08-02 17:54:39
Assigner mitre
State PUBLISHED

Description

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any students files by visiting /assets/studentfiles/<studentId>-<filename>