PT-2020-18943 · Os4Ed · Opensis

Yuri Kramarz

·

Published

2020-09-01

·

Updated

2022-05-31

·

CVE-2020-6129

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openSIS version 7.3
Description The issue concerns SQL injection vulnerabilities in the course period id parameters used in openSIS pages, specifically in the CpSessionSet.php page. An attacker can exploit this by making an authenticated HTTP request.
Recommendations For openSIS version 7.3, consider restricting access to the CpSessionSet.php page and avoid using the course period id parameter in this page until a fix is available. As a temporary workaround, restrict the course period id parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6129

Affected Products

Opensis