CVE-2021-40635: SQL Injection
Published Mar 3, 2022
·Updated
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.
Affected Software
1 affected component
OS4ED openSIS=8.0
Event History
Mar 3, 2022
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-40635.
2
What is the severity of CVE-2021-40635?
The severity of CVE-2021-40635 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2021-40635?
CVE-2021-40635 affects OS4ED openSIS 8.0.
4
What is the impact of CVE-2021-40635?
CVE-2021-40635 allows an attacker to perform SQL injection and extract information from the database.
5
Is there a fix for CVE-2021-40635?
The vendor or developer of OS4ED openSIS should release a patch or update to fix the SQL injection vulnerability.