CVE-2020-6138: SQL Injection
Published Sep 1, 2020
·Updated
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The uname parameter in the password reset page /opensis/ResetUserInfo.php is vulnerable to SQL injection An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
1 affected component
OS4ED openSIS=7.3
Event History
Sep 1, 2020
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-6138?
CVE-2020-6138 is a SQL injection vulnerability that exists in the password reset functionality of OS4Ed openSIS 7.3.
2
How severe is CVE-2020-6138?
CVE-2020-6138 has a severity level of 9.8 (critical).
3
What is the affected software for CVE-2020-6138?
The affected software for CVE-2020-6138 is OS4Ed openSIS 7.3.
4
How can CVE-2020-6138 be exploited?
CVE-2020-6138 can be exploited by sending a malicious HTTP request to the password reset page's uname parameter.
5
Is there a fix available for CVE-2020-6138?
Yes, a fix for CVE-2020-6138 is available. Updating to a patched version of OS4Ed openSIS 7.3 is recommended.