Vulnerabilities > Os4Ed > Opensis > 7.3

DATE CVE VULNERABILITY TITLE RISK
2020-09-01 CVE-2020-6117 SQL Injection vulnerability in Os4Ed Opensis 7.3
SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3.
network
low complexity
os4ed CWE-89
8.8
2020-08-24 CVE-2020-6637 SQL Injection vulnerability in Os4Ed Opensis 7.3
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
network
low complexity
os4ed CWE-89
critical
9.8
2020-07-01 CVE-2020-13383 Path Traversal vulnerability in Os4Ed Opensis
openSIS through 7.4 allows Directory Traversal.
network
low complexity
os4ed CWE-22
7.5
2020-07-01 CVE-2020-13382 Missing Authentication for Critical Function vulnerability in Os4Ed Opensis
openSIS through 7.4 has Incorrect Access Control.
network
low complexity
os4ed CWE-306
critical
9.1
2020-07-01 CVE-2020-13381 SQL Injection vulnerability in Os4Ed Opensis
openSIS through 7.4 allows SQL Injection.
network
low complexity
os4ed CWE-89
critical
9.8
2020-07-01 CVE-2020-13380 SQL Injection vulnerability in Os4Ed Opensis
openSIS before 7.4 allows SQL Injection.
network
low complexity
os4ed CWE-89
critical
9.8