Show filters
65 Total Results
Displaying 11-20 of 65
Sort by:
Attacker Value
Unknown
CVE-2021-40636
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
0
Attacker Value
Unknown
CVE-2021-40635
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.
0
Attacker Value
Unknown
CVE-2021-41679
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.
0
Attacker Value
Unknown
CVE-2021-41678
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.
0
Attacker Value
Unknown
CVE-2021-41677
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.
0
Attacker Value
Unknown
CVE-2021-40618
Disclosure Date: October 12, 2021 (last updated February 23, 2025)
An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONT_PSWD parameters in HoldAddressFields.php.
0
Attacker Value
Unknown
CVE-2021-40617
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
0
Attacker Value
Unknown
CVE-2021-40543
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file.
0
Attacker Value
Unknown
CVE-2021-40542
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.
0
Attacker Value
Unknown
CVE-2021-40651
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
0