Vulnerability index

Browse CVEs

81 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opensis CRITICAL 9.8
CVE-2021-41677

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue …

No fix yet
Fix from $2,300 2021-11-30
Opensis CRITICAL 9.8
CVE-2021-40618

An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONT_PSWD par…

No fix yet
Fix from $2,300 2021-10-12
Opensis CRITICAL 9.8
CVE-2021-40617EPSS 5%

An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.

No fix yet
Fix from $2,300 2021-10-11
Opensis CRITICAL 9.8
CVE-2021-40543

Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid']…

No fix yet
Fix from $2,300 2021-10-11
Opensis MEDIUM 6.1
CVE-2021-40542

Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the lin…

No fix yet
Fix from $1,600 2021-10-11
Opensis MEDIUM 6.5
CVE-2021-40651EPSS 18%

OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary fi…

No fix yet
Fix from $1,600 2021-09-29
Opensis HIGH 8.8
CVE-2021-40309

A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. T…

No fix yet
Fix from $1,950 2021-09-24
Opensis MEDIUM 5.4
CVE-2021-40310

OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn par…

No fix yet
Fix from $1,600 2021-09-24
Opensis CRITICAL 9.8
CVE-2021-27341

OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.

Fix: after 7.6
Fix from $2,300 2021-09-16
Opensis MEDIUM 6.1
CVE-2021-27340

OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.

Fix: after 7.6
Fix from $1,600 2021-09-16
Opensis CRITICAL 9.8
CVE-2021-39377

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQ…

No fix yet
Fix from $2,300 2021-09-01
Opensis CRITICAL 9.8
CVE-2021-39378EPSS 23%

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQ…

No fix yet
Fix from $2,300 2021-09-01
Opensis CRITICAL 9.8
CVE-2021-39379

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQ…

No fix yet
Fix from $2,300 2021-09-01
Opensis CRITICAL 9.8
CVE-2021-40353

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue …

No fix yet
Fix from $2,300 2021-09-01
Opensis MEDIUM 6.1
CVE-2020-27409

OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.

Fix: 7.5+
Fix from $1,600 2020-12-04
Opensis HIGH 7.5
CVE-2020-27408

OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker …

Fix: after 7.6
Fix from $1,950 2020-12-04
Opensis CRITICAL 9.8
CVE-2020-6142EPSS 9%

A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can cause local …

No fix yet
Fix from $2,300 2020-09-01
Opensis CRITICAL 9.8
CVE-2020-6143EPSS 6%

A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in ins…

No fix yet
Fix from $2,300 2020-09-01
Opensis CRITICAL 9.8
CVE-2020-6144EPSS 6%

A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in ins…

No fix yet
Fix from $2,300 2020-09-01
Opensis CRITICAL 9.8
CVE-2020-6137

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email parameter in the password reset p…

No fix yet
Fix from $2,300 2020-09-01
Opensis CRITICAL 9.8
CVE-2020-6138

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The uname parameter in the password reset page /opensis/…

No fix yet
Fix from $2,300 2020-09-01
Opensis CRITICAL 9.8
CVE-2020-6139

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The username_stf_email parameter in the password reset p…

No fix yet
Fix from $2,300 2020-09-01
Opensis CRITICAL 9.8
CVE-2020-6140

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email parameter in the password reset p…

No fix yet
Fix from $2,300 2020-09-01
Opensis CRITICAL 9.8
CVE-2020-6141

An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL i…

No fix yet
Fix from $2,300 2020-09-01
Opensis HIGH 8.8
CVE-2020-6136

An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can …

No fix yet
Fix from $1,950 2020-09-01
Opensis HIGH 8.8
CVE-2020-6135

An exploitable SQL injection vulnerability exists in the Validator.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead …

No fix yet
Fix from $1,950 2020-09-01
Opensis HIGH 8.8
CVE-2020-6124

An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email parameter in the page EmailChe…

No fix yet
Fix from $1,950 2020-09-01
Opensis HIGH 8.8
CVE-2020-6125

An exploitable SQL injection vulnerability exists in the GetSchool.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead …

No fix yet
Fix from $1,950 2020-09-01
Opensis HIGH 8.8
CVE-2020-6126

SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. The course_period_id parameter in the page CoursePeriodMod…

No fix yet
Fix from $1,950 2020-09-01
Opensis HIGH 8.8
CVE-2020-6127

SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. The id parameter in the page CoursePeriodModal.php is vuln…

No fix yet
Fix from $1,950 2020-09-01