OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/OS4ED/openSIS-Classic | release notes |
https://www.os4ed.com/ | product |
https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38885 | vendor advisory |