Description
openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details from modules/messaging/SentMail.php by supplying an arbitrary mail_id value.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
9.3
Credits
Daniel Celis
References
fluidattacks.com/es/advisories/melanie
fluidattacks.com/es/advisories/melanie
github.com/...ommit/c45d43146167324bae06bdf09de3e4bd2e5e478f
github.com/OS4ED/openSIS-Classic