First published: Tue Sep 01 2020(Updated: )
SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassScheduleSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6131 is a SQL injection vulnerability in the course_period_id parameters used in OS4Ed openSIS 7.3 pages.
CVE-2020-6131 has a severity rating of 8.8, which is considered high.
OS4Ed OpenSIS version 7.3 is affected by CVE-2020-6131.
An attacker can exploit CVE-2020-6131 by making an authenticated HTTP request with a malicious course_period_id parameter.
Yes, it is recommended to update to a version of OS4Ed OpenSIS that is not affected by CVE-2020-6131.