2023-11-20 00:00:00
mitre
PUBLISHED
The Community Edition version 9.0 of OS4EDs openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever an admin generates a database backup, the backup is stored in the web root while the file name has a format of "opensisBackup