Vulnerabilities > Os4Ed > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-11-30 | CVE-2021-41677 | SQL Injection vulnerability in Os4Ed Opensis 8.0 A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. | 6.8 |
2021-10-11 | CVE-2021-40542 | Cross-site Scripting vulnerability in Os4Ed Opensis 8.0 Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). | 4.3 |
2021-09-29 | CVE-2021-40651 | Path Traversal vulnerability in Os4Ed Opensis 8.0 OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file. | 4.0 |
2021-09-24 | CVE-2021-40309 | SQL Injection vulnerability in Os4Ed Opensis 8.0 A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. | 6.5 |
2021-09-16 | CVE-2021-27340 | Cross-site Scripting vulnerability in Os4Ed Opensis 7.3/7.6 OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter. | 4.3 |
2020-12-04 | CVE-2020-27409 | Cross-site Scripting vulnerability in Os4Ed Opensis 7.3 OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter. | 4.3 |
2020-12-04 | CVE-2020-27408 | Inadequate Encryption Strength vulnerability in Os4Ed Opensis 7.3/7.6 OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users. | 5.0 |
2020-09-01 | CVE-2020-6136 | SQL Injection vulnerability in Os4Ed Opensis 7.3 An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. | 6.5 |
2020-09-01 | CVE-2020-6135 | SQL Injection vulnerability in Os4Ed Opensis 7.3 An exploitable SQL injection vulnerability exists in the Validator.php functionality of OS4Ed openSIS 7.3. | 6.5 |
2020-09-01 | CVE-2020-6134 | SQL Injection vulnerability in Os4Ed Opensis 7.3 SQL injection vulnerabilities exist in the ID parameters of OS4Ed openSIS 7.3 pages. | 6.5 |