Executive brief
openSIS, a student information system used by educational institutions, contains a security flaw in its student management module. An authenticated user with low-level permissions can bypass security controls to modify or overwrite the records of other students and users. This could lead to unauthorized changes to sensitive academic data, personal information, or administrative records, compromising the integrity of the school's database.
Technical details
An improper access control vulnerability exists in the 'Student.php' component of openSIS versions 9.2 and earlier. The flaw allows an authenticated attacker with low-level privileges to bypass authorization checks and perform unauthorized database write operations. By manipulating requests to the affected script, an attacker can modify data belonging to other users. The attack is reachable over the network and does not require user interaction, though it does require valid low-privileged credentials. A proof-of-concept has been identified in public repositories.
Affected products
- OS4ED openSIS 9.2 and below
Timeline
- 2025-12-09: disclosed
- 2025-12-09: advisory