Reflected XSS Vulnerability in openSIS Classic by OS4ED
CVE-2023-38882
6.1MEDIUM
What is CVE-2023-38882?
A reflected cross-site scripting (XSS) vulnerability has been identified in the Community Edition version 9.0 of openSIS Classic by OS4ED. This security issue allows remote attackers to inject malicious JavaScript into the web browser of users by manipulating the 'include' parameter in 'ForExport.php'. Successful exploitation of this vulnerability could enable attackers to execute arbitrary scripts in the context of the user's session, which may lead to unauthorized actions or data exposure. It is crucial for users of this software to apply the necessary security measures to mitigate potential risks.
