First published: Tue Sep 01 2020(Updated: )
An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-6141 is rated as critical with a severity value of 9.8.
The SQL injection vulnerability in CVE-2020-6141 can be exploited by sending a specially crafted HTTP request that leads to SQL injection.
An attacker can exploit CVE-2020-6141 by sending an HTTP request with a malicious payload to trigger the SQL injection vulnerability.
Yes, it is recommended to update to a patched version of OS4Ed openSIS 7.3 to mitigate the SQL injection vulnerability in CVE-2020-6141.
You can find more information about CVE-2020-6141 at the following link: https://talosintelligence.com/vulnerability_reports/TALOS-2020-1081