CVE-2020-27408: OS4ED Opensis

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.

Affected products

  • OS4ED Opensis: up to and including 7.6

Published 2020-12-04. Last modified 2026-06-17.