Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Open Solutions For Education OS4Ed OpenSIS 安全漏洞
Vulnerability Description
Open Solutions For Education OS4Ed OpenSIS是美国Open Solutions For Education公司的商业级、安全、可扩展和直观的学生信息系统、学校管理软件。具有在一个安装中运行单个或多个机构的所有功能。基于 Web,php 代码,MySQL 数据库。 Open Solutions For Education OS4Ed OpenSIS v7.0至v9.1版本存在安全漏洞,该漏洞源于不安全的直接对象引用问题,可能导致未授权访问。
CVSS Information
N/A
Vulnerability Type
N/A