PT-2023-26660 · Unknown · Opensis Classic

Florian Walter

·

Publicado

2023-11-20

·

Atualizado

2023-11-30

·

CVE-2023-38880

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openSIS Classic version 9.0
Description The issue concerns a broken access control vulnerability in the database backup functionality. When an admin generates a database backup, it is stored in the web root with a filename that can be easily guessed, such as "opensisBackup.sql". This file can be accessed by any unauthenticated actor and contains a dump of the whole database, including password hashes.
Recommendations For openSIS Classic version 9.0, consider restricting access to the database backup files until a proper fix is available. As a temporary workaround, avoid using the default filename format for database backups and store them outside the web root to prevent unauthorized access.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-38880

Produtos afetados

Opensis Classic