CVE-2020-6637: SQL Injection
Published Aug 24, 2020
·Updated
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
Affected Software
1 affected component
OS4ED openSIS=7.3
Remediation
Event History
Aug 24, 2020
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-6637?
CVE-2020-6637 has a medium severity rating due to its potential for SQL injection.
2
How do I fix CVE-2020-6637?
To fix CVE-2020-6637, you should update to the latest version of openSIS that addresses this SQL injection vulnerability.
3
What are the potential impacts of CVE-2020-6637?
The potential impacts of CVE-2020-6637 include unauthorized access to sensitive data and compromise of the application's database.
4
Who is affected by CVE-2020-6637?
CVE-2020-6637 affects users of openSIS Community Edition version 7.3.
5
How does CVE-2020-6637 exploit vulnerabilities?
CVE-2020-6637 exploits vulnerabilities by injecting malicious SQL code through the USERNAME parameter in index.php.