First published: Tue Sep 01 2020(Updated: )
SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassDropSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL injection vulnerability is CVE-2020-6130.
The affected software version is OpenSIS 7.3.
The severity of this vulnerability is high with a CVSS score of 8.8.
You can find more information about this vulnerability at the following link: [CVE-2020-6130](https://talosintelligence.com/vulnerability_reports/TALOS-2020-1076).
The CWE ID for this vulnerability is CWE-89.