Reflected XSS Vulnerability in openSIS Classic by OS4ED
CVE-2023-38882

6.1MEDIUM

Key Information:

Vendor

Os4ed

Status
Vendor
CVE Published:
20 November 2023

What is CVE-2023-38882?

A reflected cross-site scripting (XSS) vulnerability has been identified in the Community Edition version 9.0 of openSIS Classic by OS4ED. This security issue allows remote attackers to inject malicious JavaScript into the web browser of users by manipulating the 'include' parameter in 'ForExport.php'. Successful exploitation of this vulnerability could enable attackers to execute arbitrary scripts in the context of the user's session, which may lead to unauthorized actions or data exposure. It is crucial for users of this software to apply the necessary security measures to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.