CVE-2020-6136: SQL Injection
Published Sep 1, 2020
·Updated
An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
1 affected component
OS4ED openSIS=7.3
Event History
Sep 1, 2020
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this SQL injection vulnerability?
The vulnerability ID of this SQL injection vulnerability is CVE-2020-6136.
2
What is the affected software version?
The affected software version is OS4Ed OpenSIS 7.3.
3
What is the severity score of CVE-2020-6136?
The severity score of CVE-2020-6136 is 8.8 (high).
4
What is the Common Weakness Enumeration (CWE) number associated with this vulnerability?
The Common Weakness Enumeration (CWE) number associated with this vulnerability is CWE-89.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the DownloadWindow.php functionality of OS4Ed OpenSIS 7.3, which can lead to SQL injection.