Vulnerabilities > Os4Ed > Opensis > 7.6

DATE CVE VULNERABILITY TITLE RISK
2023-02-13 CVE-2022-45962 SQL Injection vulnerability in Os4Ed Opensis 7.3/7.6/8.0
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
network
low complexity
os4ed CWE-89
6.5
2021-09-16 CVE-2021-27340 Cross-site Scripting vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.
network
low complexity
os4ed CWE-79
6.1
2021-09-16 CVE-2021-27341 Path Traversal vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.
network
low complexity
os4ed CWE-22
critical
9.8
2020-12-04 CVE-2020-27408 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
network
low complexity
os4ed CWE-640
7.5