CVE-2021-40617: SQL Injection
Published Oct 11, 2021
·Updated
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
Affected Software
1 affected component
OS4ED openSIS=8.0
Event History
Oct 11, 2021
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 3, 2025
Exploit Published
12:00 AM
Known Exploited
11:13 AM
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-40617.
2
What is the severity rating of CVE-2021-40617?
CVE-2021-40617 has a severity rating of 9.8 (Critical).
3
What software version is affected by CVE-2021-40617?
openSIS Community Edition version 8.0 is affected by CVE-2021-40617.
4
How does the SQL Injection vulnerability in openSIS Community Edition version 8.0 occur?
The SQL Injection vulnerability in openSIS Community Edition version 8.0 occurs through the ForgotPassUserName.php file.
5
Is there a fix available for the SQL Injection vulnerability in openSIS Community Edition version 8.0?
Yes, it is recommended to update to a patched version of openSIS Community Edition to fix the SQL Injection vulnerability.