CyberSec.Space Logo
Back to CVE Browser

CVE-2026-8406

PENDING
N/A
CVSS Severity Score
EPSS Score0.1230%
EPSS Percentile25.08th
PublishedJun 11, 2026
Last ModifiedJun 11, 2026

Vulnerability Description

openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details from modules/messaging/SentMail.php by supplying an arbitrary mail_id value.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities