Impact
openSIS Classic 9.3 contains an insecure direct object reference that allows an authenticated user in the built‑in teacher role to supply any staff_id and trigger a password reset on that account. The flaw permits privilege escalation by changing another staff member’s credentials, effectively bypassing authorization controls (CWE‑639). No additional privileges are required beyond teacher authentication.
Affected Systems
The vulnerability affects openSIS Classic version 9.3 on Linux, macOS, and Windows platforms as distributed by OS4ED. Only the default teacher role is locally implicated, but any user with that role can exercise the exploit.
Risk and Exploitability
The CVSS score of 9.3 signals a high‑severity vulnerability and the lack of an EPSS score limits the precision of the exploitation probability, though the potential impact is significant. Because the flaw is web‑based and requires an authenticated teacher session, a determined attacker can readily gain access to a staff password. The vulnerability is not listed in the CISA KEV catalog, but the consequence of unauthorized credential reset warrants immediate attention.
OpenCVE Enrichment