CVE-2023-38884: OS4ED Opensis

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'

Affected products

  • OS4ED Opensis: version 9.0 only

Published 2023-11-20. Last modified 2026-06-17.