Executive brief
openSIS Classic, a student information system used by schools to manage academic records and communications, contains a security flaw in its messaging module. An authenticated user, such as a student or staff member, can view private messages sent by other users by simply changing a message ID in their web browser. This could lead to the unauthorized exposure of sensitive school communications and personal information.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in openSIS Classic 9.3 within the messaging module. The flaw is located in 'modules/messaging/SentMail.php', where the application fails to perform adequate authorization checks when a user requests message details. By supplying an arbitrary 'mail_id' value in the request, any authenticated user with access to the messaging module can bypass intended access controls to view sent-message details and download attachments belonging to other users. A patch has been committed to the official repository to enforce proper authorization checks in 'SentMail.php' and 'DownloadWindow.php'.
Affected products
- OS4ED openSIS Classic 9.3
Timeline
- 2026-06-11: advisory: NVD and Fluid Attacks published the advisory
- 2026-06-11: disclosed
- 2026-06-11: patched: Fix committed to GitHub repository