Broken Access Control in OS4ED's openSIS Classic Database Backup Functionality
CVE-2023-38880
9.8CRITICAL
What is CVE-2023-38880?
The openSIS Classic Community Edition version 9.0 features a broken access control vulnerability in its database backup functionality. When an administrator creates a database backup, the backup file is stored in the web root directory and follows a predictable naming convention, such as 'opensisBackup.sql'. This design flaw allows any unauthenticated user to access the backup file, which contains a complete dump of the database, including sensitive data like password hashes. As a result, this vulnerability poses a significant risk to user data integrity and confidentiality.
