Opendesa develops OpenSID, a village-governance and administrative-management platform deployed in Indonesian municipalities, with a vulnerability footprint centered on web-application input handling and file-upload controls. The recurring weakness classes—including cross-site request forgery, cross-site scripting, and unrestricted file uploads—reflect the typical attack surface of web-facing administrative software that processes user-supplied data and document submissions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opendesa over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13038CRITICAL OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uploading arbitrary PHP code via a | Jul 1, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-13040HIGH OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.php/man_user/insert URI. | Jul 1, 2018 | 8.8 | 22 | NO | NO |
CVE-2018-13039MEDIUM OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI. | Jul 1, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opendesa.
Media articles that mention a CVE ID that affects a product developed by Opendesa — matched by CVE ID, not by vendor name.