First published: Tue Sep 01 2020(Updated: )
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An attacker can send an HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6143 is a remote code execution vulnerability in the install functionality of OS4Ed openSIS 7.4.
CVE-2020-6143 has a severity rating of 9.8 (Critical).
CVE-2020-6143 allows for injection of PHP code into the Data.php file through a password variable in install/Step5.php.
OS4Ed OpenSIS version 7.4 is affected by CVE-2020-6143.
A patch or update may be available to fix CVE-2020-6143, check with the OS4Ed OpenSIS vendor for the latest information.