CVE-2020-6128: SQL Injection
SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. The meetdate parameter in the page CoursePeriodModal.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6128?
CVE-2020-6128 is a SQL injection vulnerability in the CoursePeriodModal.php page of OS4Ed openSIS 7.3.
How severe is CVE-2020-6128?
CVE-2020-6128 has a severity rating of 8.8 (high).
What is the affected software version of CVE-2020-6128?
The affected software version of CVE-2020-6128 is OS4Ed openSIS 7.3.
How can an attacker exploit CVE-2020-6128?
An attacker can exploit CVE-2020-6128 by sending a specially crafted HTTP request containing malicious SQL code in the meet_date parameter of the CoursePeriodModal.php page.
Is there any fix available for CVE-2020-6128?
There is currently no known fix or patch available for CVE-2020-6128. It is recommended to apply security updates or contact the vendor for further information.