Vulnerabilities > Os4Ed

DATE CVE VULNERABILITY TITLE RISK
2021-09-24 CVE-2021-40309 SQL Injection vulnerability in Os4Ed Opensis 8.0
A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0.
network
low complexity
os4ed CWE-89
8.8
2021-09-24 CVE-2021-40310 Cross-site Scripting vulnerability in Os4Ed Opensis 8.0
OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn parameter.
network
low complexity
os4ed CWE-79
5.4
2021-09-16 CVE-2021-27340 Cross-site Scripting vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.
network
low complexity
os4ed CWE-79
6.1
2021-09-16 CVE-2021-27341 Path Traversal vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.
network
low complexity
os4ed CWE-22
critical
9.8
2021-09-01 CVE-2021-39377 SQL Injection vulnerability in Os4Ed Opensis 8.0
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
network
low complexity
os4ed CWE-89
critical
9.8
2021-09-01 CVE-2021-39378 SQL Injection vulnerability in Os4Ed Opensis 8.0
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
network
low complexity
os4ed CWE-89
critical
9.8
2021-09-01 CVE-2021-39379 SQL Injection vulnerability in Os4Ed Opensis 8.0
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
network
low complexity
os4ed CWE-89
critical
9.8
2021-09-01 CVE-2021-40353 SQL Injection vulnerability in Os4Ed Opensis 8.0
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
network
low complexity
os4ed CWE-89
critical
9.8
2020-12-04 CVE-2020-27409 Cross-site Scripting vulnerability in Os4Ed Opensis 7.3
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
network
low complexity
os4ed CWE-79
6.1
2020-12-04 CVE-2020-27408 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
network
low complexity
os4ed CWE-640
7.5