CVE-2020-6117: SQL Injection
Published Sep 1, 2020
·Updated
SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bday parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
1 affected component
OS4ED openSIS=7.3
Event History
Sep 1, 2020
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-6117?
CVE-2020-6117 is a SQL injection vulnerability in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3.
2
How severe is CVE-2020-6117?
CVE-2020-6117 has a severity rating of 8.8 (high).
3
What is the affected software of CVE-2020-6117?
CVE-2020-6117 affects OS4Ed OpenSIS 7.3.
4
How can an attacker exploit CVE-2020-6117?
An attacker can exploit CVE-2020-6117 by sending a malicious request to the bday parameter in the CheckDuplicateStudent.php page, allowing them to perform SQL injection.
5
Is there any reference documentation for CVE-2020-6117?
Yes, you can refer to the Talos Intelligence vulnerability report for more information about CVE-2020-6117.