PT-2020-7770 · Unknown · Open-School Community Edition

Published

2020-02-08

·

Updated

2020-02-10

·

CVE-2014-9127

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Open-School Community Edition version 2.2
Description: The issue concerns improper access restriction to the export functionality. Remote authenticated users can obtain sensitive information by exploiting this weakness. Specifically, the "r" parameter with the value "export" in the "index.php" endpoint can be manipulated to gain access to sensitive data.
Recommendations: For Open-School Community Edition version 2.2, consider restricting access to the export functionality to prevent unauthorized users from obtaining sensitive information. As a temporary workaround, restrict access to the "index.php" endpoint with the "r" parameter set to "export" until a proper fix is implemented.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9127

Affected Products

Open-School Community Edition