CVE-2023-38883
- EPSS 0.63%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax...
CVE-2023-38884
- EPSS 0.88%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'
CVE-2023-38885
- EPSS 0.37%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.
CVE-2022-45962
- EPSS 0.9%
- Veröffentlicht 13.02.2023 21:15:13
- Zuletzt bearbeitet 21.03.2025 19:15:40
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
CVE-2022-27041
- EPSS 1.29%
- Veröffentlicht 11.04.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:00
Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.
CVE-2021-40637
- EPSS 0.77%
- Veröffentlicht 03.03.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:24:29
OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user.
CVE-2021-40636
- EPSS 1.26%
- Veröffentlicht 03.03.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:29
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
CVE-2021-40635
- EPSS 1.26%
- Veröffentlicht 03.03.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:28
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.
CVE-2021-41679
- EPSS 1.31%
- Veröffentlicht 30.11.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:37
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.
CVE-2021-41678
- EPSS 1.31%
- Veröffentlicht 30.11.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:37
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.