Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhqf-328w-9ggv

Опубликовано: 20 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/-'

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/-'

EPSS

Процентиль: 57%
0.00356
Низкий

7.5 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'

EPSS

Процентиль: 57%
0.00356
Низкий

7.5 High

CVSS3

Дефекты

CWE-639