CVE-2023-38884

Publication date

2023-11-20 00:00:00

Family

mitre

State

PUBLISHED

Description

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any students files by visiting /assets/studentfiles/-