Executive brief
openSIS Classic, a student information system used to manage school operations, contains a security flaw in its messaging system. An authorized user, such as a student or staff member, could exploit this vulnerability to access sensitive files stored on the school's server that they are not permitted to see. This could lead to the exposure of private administrative data or system configuration files.
Technical details
A path traversal vulnerability (CWE-22) exists in openSIS Classic 9.3 within the legacy messaging module. The flaw is located in the functionality responsible for downloading attachments from sent mail. An authenticated attacker can provide specially crafted input containing path traversal sequences (e.g., ../) to bypass directory restrictions. This allows the attacker to read arbitrary files on the underlying server filesystem with the privileges of the web server process. The attack requires network access and valid user credentials but no special administrative privileges.
Affected products
- OS4ED openSIS Classic 9.3
Timeline
- 2026-07-14: advisory: NVD and Fluid Attacks published the advisory