First published: Mon Oct 11 2021(Updated: )
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-40617.
CVE-2021-40617 has a severity rating of 9.8 (Critical).
openSIS Community Edition version 8.0 is affected by CVE-2021-40617.
The SQL Injection vulnerability in openSIS Community Edition version 8.0 occurs through the ForgotPassUserName.php file.
Yes, it is recommended to update to a patched version of openSIS Community Edition to fix the SQL Injection vulnerability.