Impact
The vulnerability in openSIS Classic 9.3 permits an authenticated attacker to read files located outside the intended directory by supplying crafted path traversal sequences in the legacy sent‑mail attachment download API. Because the application does not validate the path component supplied by the attacker, any file on the server that is readable by the web server process can be exfiltrated. The weakness is a classic directory traversal flaw (CWE‑22) that exposes confidentiality risks and can be used by a malicious user to compromise local secrets, configuration files, or system binaries.
Affected Systems
The product OS4ED’s openSIS Classic 9.3 on Linux, macOS, and Windows platforms is affected. The legacy messaging sent‑mail attachment download feature, when enabled and accessed by an authenticated user, allows exploitation. No versions before 9.3 are mentioned; the vulnerability exists only in release 9.3.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score below 1 % indicates low exploitation probability. The vulnerability is not listed in CISA KEV catalog. Exploitation requires valid authentication, so the attack surface is limited to legitimate users or compromised accounts. An attacker can obtain arbitrary files in the server’s file system and potentially pivot to further compromise the system.
OpenCVE Enrichment