First published: Tue Sep 01 2020(Updated: )
An exploitable SQL injection vulnerability exists in the Validator.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the SQL injection vulnerability in OS4Ed openSIS 7.3 is CVE-2020-6135.
The severity of CVE-2020-6135 is high with a CVSS score of 8.8.
The affected software for CVE-2020-6135 is OS4Ed openSIS 7.3.
The SQL injection vulnerability in OS4Ed openSIS 7.3 occurs in the Validator.php functionality when processing a specially crafted HTTP request.
An attacker can exploit CVE-2020-6135 by making an authenticated HTTP request with a specially crafted payload to trigger the SQL injection vulnerability.