Cross-Site Request Forgery Flaw in OpenSIS Classic Community Edition
CVE-2023-38885
8.8HIGH
What is CVE-2023-38885?
The OpenSIS Classic Community Edition version 9.0 is susceptible to cross-site request forgery (CSRF) attacks due to a lack of protection mechanisms. This vulnerability can be exploited by an attacker to deceive an authenticated user into executing unintended actions. Without proper CSRF safeguards, the application permits unauthorized state-changing requests, potentially compromising user accounts and sensitive data.
