Os4ed

Opensis

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 02.04.2025 21:15:32
  • Zuletzt bearbeitet 29.04.2025 13:48:51

OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.

  • EPSS 1.3%
  • Veröffentlicht 02.04.2025 21:15:32
  • Zuletzt bearbeitet 17.07.2025 18:24:23

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.

Exploit
  • EPSS 3.03%
  • Veröffentlicht 08.11.2024 19:15:06
  • Zuletzt bearbeitet 17.07.2025 17:32:21

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to i...

Exploit
  • EPSS 85.17%
  • Veröffentlicht 15.10.2024 19:15:16
  • Zuletzt bearbeitet 17.07.2025 17:33:12

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perf...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 02.10.2024 17:15:20
  • Zuletzt bearbeitet 17.07.2025 17:36:39

OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

  • EPSS 0.17%
  • Veröffentlicht 20.11.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:14:21

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into any of th...

  • EPSS 11.97%
  • Veröffentlicht 20.11.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:14:21

The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.

  • EPSS 0.14%
  • Veröffentlicht 20.11.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:14:21

The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever an admin generates a database backup, the backup is stored in the web root while the file name has a...

  • EPSS 0.17%
  • Veröffentlicht 20.11.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:14:21

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'incl...

  • EPSS 0.17%
  • Veröffentlicht 20.11.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:14:21

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax...