CVE-2025-22924
- EPSS 0.19%
- Veröffentlicht 02.04.2025 21:15:32
- Zuletzt bearbeitet 29.04.2025 13:48:51
OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
CVE-2025-22923
- EPSS 1.3%
- Veröffentlicht 02.04.2025 21:15:32
- Zuletzt bearbeitet 17.07.2025 18:24:23
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
CVE-2024-51211
- EPSS 3.03%
- Veröffentlicht 08.11.2024 19:15:06
- Zuletzt bearbeitet 17.07.2025 17:32:21
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to i...
CVE-2024-35584
- EPSS 85.17%
- Veröffentlicht 15.10.2024 19:15:16
- Zuletzt bearbeitet 17.07.2025 17:33:12
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perf...
CVE-2024-46626
- EPSS 0.25%
- Veröffentlicht 02.10.2024 17:15:20
- Zuletzt bearbeitet 17.07.2025 17:36:39
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
CVE-2023-38881
- EPSS 0.17%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into any of th...
CVE-2023-38879
- EPSS 11.97%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.
CVE-2023-38880
- EPSS 0.14%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever an admin generates a database backup, the backup is stored in the web root while the file name has a...
CVE-2023-38882
- EPSS 0.17%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'incl...
CVE-2023-38883
- EPSS 0.17%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax...