Vulnerabilities > Os4Ed > Opensis > 7.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-13 | CVE-2022-45962 | SQL Injection vulnerability in Os4Ed Opensis 7.3/7.6/8.0 Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php. | 6.5 |
2021-09-16 | CVE-2021-27340 | Cross-site Scripting vulnerability in Os4Ed Opensis 7.3/7.6 OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter. | 4.3 |
2021-09-16 | CVE-2021-27341 | Path Traversal vulnerability in Os4Ed Opensis 7.3/7.6 OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter. | 7.5 |
2020-12-04 | CVE-2020-27409 | Cross-site Scripting vulnerability in Os4Ed Opensis 7.3 OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter. | 4.3 |
2020-12-04 | CVE-2020-27408 | Inadequate Encryption Strength vulnerability in Os4Ed Opensis 7.3/7.6 OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users. | 5.0 |
2020-09-01 | CVE-2020-6142 | Path Traversal vulnerability in Os4Ed Opensis 7.3 A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. | 7.5 |
2020-09-01 | CVE-2020-6140 | SQL Injection vulnerability in Os4Ed Opensis 7.3 SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. | 7.5 |
2020-09-01 | CVE-2020-6139 | SQL Injection vulnerability in Os4Ed Opensis 7.3 SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. | 7.5 |
2020-09-01 | CVE-2020-6138 | SQL Injection vulnerability in Os4Ed Opensis 7.3 SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. | 7.5 |
2020-09-01 | CVE-2020-6137 | SQL Injection vulnerability in Os4Ed Opensis 7.3 SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. | 7.5 |