Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9612 | An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members. |
Thu, 17 Jul 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Os4ed
Os4ed opensis |
|
| CPEs | cpe:2.3:a:os4ed:opensis:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Os4ed
Os4ed opensis |
Mon, 21 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Thu, 03 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-21T18:26:32.580Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2025-22931
Updated: 2025-04-21T18:22:06.623Z
Status : Analyzed
Published: 2025-04-03T14:15:29.823
Modified: 2025-07-17T18:17:08.607
Link: CVE-2025-22931
No data.
OpenCVE Enrichment
No data.
EUVD