First published: Mon Oct 11 2021(Updated: )
Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40543 is a SQL injection vulnerability in Opensis-Classic version 8.0.
CVE-2021-40543 affects Opensis-Classic version 8.0 due to a lack of sanitization of input data.
CVE-2021-40543 has a severity rating of critical (9.8).
To fix the SQL injection vulnerability CVE-2021-40543, patch or upgrade Opensis-Classic to a version that includes the necessary sanitization of input data.
More information about CVE-2021-40543 can be found at the following reference: https://github.com/OS4ED/openSIS-Classic/issues/191