CVE-2020-6137: SQL Injection
Published Sep 1, 2020
·Updated
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The passwordstfemail parameter in the password reset page /opensis/ResetUserInfo.php is vulnerable to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
1 affected component
OS4ED openSIS=7.3
Event History
Sep 1, 2020
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-6137.
2
What is the title of this vulnerability?
The title of this vulnerability is 'SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.'
3
What is the severity of CVE-2020-6137?
The severity of CVE-2020-6137 is critical with a severity value of 9.8.
4
What software is affected by CVE-2020-6137?
The OS4Ed openSIS version 7.3 is affected by CVE-2020-6137.
5
How can an attacker exploit CVE-2020-6137?
An attacker can exploit CVE-2020-6137 by sending an HTTP request with a malicious payload to the password reset page /opensis/ResetUserInfo.php.