An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
The attacker sends a crafted HTTP POST request to the /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename endpoint, manipulating the filename parameter to contain path traversal sequences (e.g., ../). The server does not properly validate the path passed in the parameter, allowing it to escape the allowed directory. As a result, it is possible to read or overwrite system files accessible to the web server process.
An attacker can gain unauthorized access to sensitive files on the server (e.g., configuration files, student data) or overwrite them, violating the confidentiality and integrity of stored data.
Apply patches available from the vendor according to references. The vendor's repository is available at https://github.com/OS4ED/openSIS-Classic. Until an update is applied, it is recommended to restrict network access to the openSIS instance and monitor suspicious requests to the Modules.php endpoint.
OS4ED openSIS versions 8.0 through 9.1 (openSIS-Classic)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NOs4ed Opensis
APPOs4Ed8.0 – 9.1
Related vulnerabilities
SQL Injection w OpenSIS via parametry student_id i TRANSFER[SCHOOL]
SQL Injection w Os4Ed openSIS — parametr filter_id
Path traversal w openSIS umożliwia nieautoryzowany dostęp do plików
SQL Injection w OS4ED openSIS — parametr cp_id w module wiadomości
SQL injection w OS4Ed openSIS via parametr groupid w Group.php