Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability impacts openSIS Classic, a student information system, allowing authenticated teachers to reset the passwords of any staff member by manipulating a staff identifier. The main concern is confirming relevance and exposure within your environment.
- Teachers can reset any staff password.
- Critical student data system at risk.
- Verify if your openSIS Classic is affected.
Attack Path
How an attacker could exploit the issue
An attacker with a teacher's account can access the school information update feature. By manipulating the staff ID, they can trigger a password reset for any staff account, potentially gaining unauthorized access to sensitive student data.
- Authenticated teacher role required.
- Arbitrary staff ID selection.
- Unauthorized password reset and data access.
Live Threat
Current exploitation, exposure, and threat context
An authenticated teacher could reset any staff member's password by manipulating the `staff_id` parameter, potentially leading to unauthorized access to sensitive school information. This occurs when the system's password reset function is used to target specific staff accounts.
- Staff account credentials.
- Authenticated teacher manipulates `staff_id`.
- Unauthorized access to staff accounts.
Operational Fix
Recommended remediation, mitigation, and detection steps
The School Information System owner, likely the IT or Application Support team, should lead the response to this vulnerability. The first practical step involves identifying all instances of openSIS Classic, confirming their network reachability and criticality, and then assigning ownership for remediation planning.
- Identify affected systems and owners.
- Verify external and internal reachability.
- Plan remediation based on risk.