Vulnerabilities > Os4Ed > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-30 CVE-2021-41677 SQL Injection vulnerability in Os4Ed Opensis 8.0
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
network
os4ed CWE-89
6.8
2021-10-11 CVE-2021-40542 Cross-site Scripting vulnerability in Os4Ed Opensis 8.0
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS).
network
os4ed CWE-79
4.3
2021-09-29 CVE-2021-40651 Path Traversal vulnerability in Os4Ed Opensis 8.0
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
network
low complexity
os4ed CWE-22
4.0
2021-09-24 CVE-2021-40309 SQL Injection vulnerability in Os4Ed Opensis 8.0
A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0.
network
low complexity
os4ed CWE-89
6.5
2021-09-16 CVE-2021-27340 Cross-site Scripting vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.
network
os4ed CWE-79
4.3
2020-12-04 CVE-2020-27409 Cross-site Scripting vulnerability in Os4Ed Opensis 7.3
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
network
os4ed CWE-79
4.3
2020-12-04 CVE-2020-27408 Inadequate Encryption Strength vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
network
low complexity
os4ed CWE-326
5.0
2020-09-01 CVE-2020-6136 SQL Injection vulnerability in Os4Ed Opensis 7.3
An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3.
network
low complexity
os4ed CWE-89
6.5
2020-09-01 CVE-2020-6135 SQL Injection vulnerability in Os4Ed Opensis 7.3
An exploitable SQL injection vulnerability exists in the Validator.php functionality of OS4Ed openSIS 7.3.
network
low complexity
os4ed CWE-89
6.5
2020-09-01 CVE-2020-6134 SQL Injection vulnerability in Os4Ed Opensis 7.3
SQL injection vulnerabilities exist in the ID parameters of OS4Ed openSIS 7.3 pages.
network
low complexity
os4ed CWE-89
6.5