CVE-2020-13380: SQL Injection
Published Jul 1, 2020
·Updated
openSIS before 7.4 allows SQL Injection.
Affected Software
1 affected component
OS4ED openSIS<=7.4
Remediation
Event History
Jul 1, 2020
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13380?
CVE-2020-13380 has a medium severity rating due to the potential for SQL injection attacks.
2
How do I fix CVE-2020-13380?
To fix CVE-2020-13380, upgrade to openSIS version 7.4 or later.
3
What versions are affected by CVE-2020-13380?
Versions of openSIS earlier than 7.4 are affected by CVE-2020-13380.
4
What type of vulnerability is CVE-2020-13380?
CVE-2020-13380 is an SQL Injection vulnerability that allows attackers to manipulate the database.
5
Is CVE-2020-13380 easy to exploit?
CVE-2020-13380 can be relatively easy to exploit if adequate security measures are not in place.