CVE-2021-39377: SQL Injection
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39377?
CVE-2021-39377 is a SQL Injection vulnerability in openSIS 8.0 when MySQL (MariaDB) is used as the application database.
How does CVE-2021-39377 affect openSIS?
CVE-2021-39377 allows a malicious attacker to execute SQL commands on the MySQL (MariaDB) database in openSIS 8.0 through the index.php username parameter.
What is the severity of CVE-2021-39377?
The severity of CVE-2021-39377 is critical with a CVSS score of 9.8.
How can I fix CVE-2021-39377?
To fix CVE-2021-39377, you should update openSIS to the latest version or apply the necessary patches provided by the vendor.
Where can I find more information about CVE-2021-39377?
You can find more information about CVE-2021-39377 on the official openSIS website, GitHub repository, and the CVE-2021-39377 security advisory.