CVE-2023-38884
- EPSS 0.36%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'
CVE-2023-38885
- EPSS 0.27%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:21
OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.
CVE-2022-45962
- EPSS 0.45%
- Veröffentlicht 13.02.2023 21:15:13
- Zuletzt bearbeitet 21.03.2025 19:15:40
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
CVE-2022-27041
- EPSS 0.44%
- Veröffentlicht 11.04.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:00
Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.
CVE-2021-40637
- EPSS 0.27%
- Veröffentlicht 03.03.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:24:29
OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user.
CVE-2021-40636
- EPSS 0.38%
- Veröffentlicht 03.03.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:29
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
CVE-2021-40635
- EPSS 0.38%
- Veröffentlicht 03.03.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:28
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.
CVE-2021-41679
- EPSS 0.56%
- Veröffentlicht 30.11.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:37
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.
CVE-2021-41678
- EPSS 0.56%
- Veröffentlicht 30.11.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:37
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.
CVE-2021-41677
- EPSS 0.38%
- Veröffentlicht 30.11.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:37
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.