← Vulnerability feed

Vulnerability record · CVE-2020-13383 · published 1 July 2020

CVE-2020-13383: openSIS Directory Traversal Allows Unauthenticated File Read

Os4ed · Opensis

openSIS through 7.4 is vulnerable to directory traversal (CWE-22), allowing crafted path input to reach files outside the intended web directory. The flaw is remotely reachable without authentication and is rated CVSS 3.1 7.5 (HIGH), so exposed student information system instances are at risk of file disclosure.

7.5 CVSS 3.1 High EPSS 68% · top 0.7% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

openSIS through 7.4 allows Directory Traversal.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote file disclosure with public exploit references and very high EPSS, though not confirmed in CISA KEV.

What it is

openSIS through 7.4 is vulnerable to directory traversal (CWE-22), allowing crafted path input to reach files outside the intended web directory. The flaw is remotely reachable without authentication and is rated CVSS 3.1 7.5 (HIGH), so exposed student information system instances are at risk of file disclosure.

Impact

An unauthenticated attacker can read arbitrary files the web server process can access, potentially exposing configuration files, credentials and student data. The CVSS vector shows high confidentiality impact with no integrity or availability impact.

Attack surface

Reached over the network via HTTP with no authentication and no user interaction required (AV:N/PR:N/UI:N). The description does not name the specific vulnerable parameter or endpoint, so the exact request path is not documented in this record.

Exploitation

Public exploit references exist (Packet Storm advisories tagged Exploit), and EPSS is 0.67792 (99.283rd percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so confirmed in-the-wild exploitation is not established by this record.

What to do

  • Upgrade openSIS to a version containing the fix referenced in the OS4ED commit 1127ae0bb7c3a2883febeabc6b71ad8d73510de8; if no fixed release is available, apply that patch.
  • Restrict network access to openSIS instances so they are not reachable from untrusted networks, and place them behind authentication or a reverse proxy where possible.
  • Run the web server with least privilege and ensure its process account cannot read sensitive files outside the application directory.
  • Review web server and application logs for traversal patterns such as ../ and encoded variants in request paths and parameters.

Detection

  • Search HTTP access logs for traversal sequences (../, ..%2f, %2e%2e/) in URLs and query strings targeting openSIS endpoints.
  • Alert on requests to openSIS paths that return files with extensions not normally served by the application (e.g., .conf, .ini, .log, .sql).
  • Monitor for known exploit request patterns from the Packet Storm advisories against openSIS instances.
  • Baseline normal file access by the web server process and flag reads of files outside the openSIS web root.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13383 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41691Os4ed opensis sql injection vulnerabilityA SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in…EPSS 1.9%9.8CVE-2025-22926Os4ed opensis path traversal vulnerabilityAn issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modna…EPSS 0.90%9.8CVE-2025-22929Os4ed opensis sql injection vulnerabilityOS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php.EPSS 0.52%9.8CVE-2025-22930Os4ed opensis sql injection vulnerabilityOS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.EPSS 0.52%9.8CVE-2025-22928Os4ed opensis sql injection vulnerabilityOS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.EPSS 0.42%9.8CVE-2024-51211Os4ed opensis sql injection vulnerabilitySQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to impr…EPSS 2.3%9.8CVE-2023-38880Os4ed opensis vulnerabilityThe Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever…EPSS 0.96%9.8CVE-2021-41679Os4ed opensis sql injection vulnerabilityA SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2020-13383), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.