Security Advisory
CVE-2023-38884
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any students files by visiting /assets/studentfiles/<studentId>-<filename>