Vulnerability record · CVE-2020-13383 · published 1 July 2020
CVE-2020-13383: openSIS Directory Traversal Allows Unauthenticated File Read
Os4ed · Opensis
openSIS through 7.4 is vulnerable to directory traversal (CWE-22), allowing crafted path input to reach files outside the intended web directory. The flaw is remotely reachable without authentication and is rated CVSS 3.1 7.5 (HIGH), so exposed student information system instances are at risk of file disclosure.
Description
openSIS through 7.4 allows Directory Traversal.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file disclosure with public exploit references and very high EPSS, though not confirmed in CISA KEV.
What it is
openSIS through 7.4 is vulnerable to directory traversal (CWE-22), allowing crafted path input to reach files outside the intended web directory. The flaw is remotely reachable without authentication and is rated CVSS 3.1 7.5 (HIGH), so exposed student information system instances are at risk of file disclosure.
Impact
An unauthenticated attacker can read arbitrary files the web server process can access, potentially exposing configuration files, credentials and student data. The CVSS vector shows high confidentiality impact with no integrity or availability impact.
Attack surface
Reached over the network via HTTP with no authentication and no user interaction required (AV:N/PR:N/UI:N). The description does not name the specific vulnerable parameter or endpoint, so the exact request path is not documented in this record.
Exploitation
Public exploit references exist (Packet Storm advisories tagged Exploit), and EPSS is 0.67792 (99.283rd percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so confirmed in-the-wild exploitation is not established by this record.
What to do
- Upgrade openSIS to a version containing the fix referenced in the OS4ED commit 1127ae0bb7c3a2883febeabc6b71ad8d73510de8; if no fixed release is available, apply that patch.
- Restrict network access to openSIS instances so they are not reachable from untrusted networks, and place them behind authentication or a reverse proxy where possible.
- Run the web server with least privilege and ensure its process account cannot read sensitive files outside the application directory.
- Review web server and application logs for traversal patterns such as ../ and encoded variants in request paths and parameters.
Detection
- Search HTTP access logs for traversal sequences (../, ..%2f, %2e%2e/) in URLs and query strings targeting openSIS endpoints.
- Alert on requests to openSIS paths that return files with extensions not normally served by the application (e.g., .conf, .ini, .log, .sql).
- Monitor for known exploit request patterns from the Packet Storm advisories against openSIS instances.
- Baseline normal file access by the web server process and flag reads of files outside the openSIS web root.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158256/openSIS-7.4-Local-File-Inclusion.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/158331/openSIS-7.4-Unauthenticated-PHP-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/OS4ED/openSIS-Responsive-Design/commit/1127ae0bb7c3a2883febeabc6b71ad8d73510de8 | PatchThird Party Advisory |
| http://packetstormsecurity.com/files/158256/openSIS-7.4-Local-File-Inclusion.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/158331/openSIS-7.4-Unauthenticated-PHP-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/OS4ED/openSIS-Responsive-Design/commit/1127ae0bb7c3a2883febeabc6b71ad8d73510de8 | PatchThird Party Advisory |
Track CVE-2020-13383 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13383), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.