OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:os4ed:opensis:*:*:*:*:community:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "7.6"
}
]
}
{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:os4ed:opensis:*:*:*:*:community:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "7.6"
}
]
}