CVE-2020-27409: XSS
Published Dec 4, 2020
·Updated
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
Affected Software
1 affected component
OS4ED openSIS<7.5
Remediation
Event History
Dec 4, 2020
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Frequently Asked Questions
1
What is CVE-2020-27409?
CVE-2020-27409 is a cross-site scripting (XSS) vulnerability in OpenSIS Community Edition before 7.5.
2
How does CVE-2020-27409 affect OpenSIS Community Edition?
CVE-2020-27409 affects OpenSIS Community Edition before version 7.5.
3
What is the severity of CVE-2020-27409?
The severity of CVE-2020-27409 is medium with a CVSS score of 6.1.
4
How can CVE-2020-27409 be exploited?
CVE-2020-27409 can be exploited through the modname parameter in SideForStudent.php.
5
How can I fix CVE-2020-27409?
To fix CVE-2020-27409, update OpenSIS Community Edition to version 7.5 or above.