Broken Access Control in OS4ED's openSIS Classic Database Backup Functionality
CVE-2023-38880
What is CVE-2023-38880?
The openSIS Classic Community Edition version 9.0 features a broken access control vulnerability in its database backup functionality. When an administrator creates a database backup, the backup file is stored in the web root directory and follows a predictable naming convention, such as 'opensisBackup.sql'. This design flaw allows any unauthenticated user to access the backup file, which contains a complete dump of the database, including sensitive data like password hashes. As a result, this vulnerability poses a significant risk to user data integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
