PT-2020-18931 · Os4Ed · Opensis

Published

2020-09-01

·

Updated

2022-07-28

·

CVE-2020-6117

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OS4Ed openSIS version 7.3
Description The issue concerns SQL injection vulnerabilities in the CheckDuplicateStudent.php page. Specifically, the bday parameter in this page is vulnerable to SQL injection. An attacker can exploit this by making an authenticated HTTP request to the "/CheckDuplicateStudent.php" endpoint.
Recommendations For OS4Ed openSIS version 7.3, consider restricting access to the CheckDuplicateStudent.php page or the bday parameter to minimize the risk of exploitation until a patch is available. Avoid using the bday parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6117

Affected Products

Opensis