Vulnerabilities
Vulnerable Software
Os4ed:  >> Opensis  >> 9.1  Security Vulnerabilities
SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php
CVSS Score
8.1
EPSS Score
0.002
Published
2025-07-15
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.
CVSS Score
9.8
EPSS Score
0.066
Published
2024-11-08
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
CVSS Score
8.8
EPSS Score
0.728
Published
2024-10-15
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-10-02


Contact Us

Shodan ® - All rights reserved