CVE-2020-6129: SQL Injection
Published Sep 1, 2020
·Updated
SQL injection vulnerabilities exist in the courseperiodid parameters used in OS4Ed openSIS 7.3 pages. The courseperiodid parameter in the page CpSessionSet.php is vulnerable to SQL injection.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.
Affected Software
1 affected component
OS4ED openSIS=7.3
Event History
Sep 1, 2020
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-6129.
2
What is the severity of CVE-2020-6129?
The severity of CVE-2020-6129 is high with a severity value of 8.8.
3
What is the affected software for CVE-2020-6129?
The affected software for CVE-2020-6129 is OS4Ed OpenSIS version 7.3.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is 89.
5
How can I fix the SQL injection vulnerabilities in OS4Ed OpenSIS 7.3?
To fix the SQL injection vulnerabilities, you should update OS4Ed OpenSIS to a patched version provided by the vendor.