First published: Fri Dec 04 2020(Updated: )
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | <7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27409 is a cross-site scripting (XSS) vulnerability in OpenSIS Community Edition before 7.5.
CVE-2020-27409 affects OpenSIS Community Edition before version 7.5.
The severity of CVE-2020-27409 is medium with a CVSS score of 6.1.
CVE-2020-27409 can be exploited through the modname parameter in SideForStudent.php.
To fix CVE-2020-27409, update OpenSIS Community Edition to version 7.5 or above.