CVE-2020-6125: SQL Injection
Published Sep 1, 2020
·Updated
An exploitable SQL injection vulnerability exists in the GetSchool.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
1 affected component
OS4ED openSIS=7.3
Event History
Sep 1, 2020
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection vulnerability?
The vulnerability ID for this SQL injection vulnerability is CVE-2020-6125.
2
What is the severity rating of CVE-2020-6125?
CVE-2020-6125 has a severity rating of 8.8 (high).
3
Which software version is affected by this vulnerability?
The OS4Ed OpenSIS version 7.3 is affected by this SQL injection vulnerability.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this SQL injection vulnerability by sending a specially crafted HTTP request.
5
Is authentication required to exploit CVE-2020-6125?
Yes, an attacker needs to make an authenticated HTTP request to exploit this vulnerability.