First published: Thu Mar 03 2022(Updated: )
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-40636 is high with a CVSS score of 7.5.
CVE-2021-40636 affects OS4ED openSIS 8.0 by allowing SQL injection in CheckDuplicateName.php, which can extract information from the database.
To fix CVE-2021-40636, apply the latest patch or update provided by OS4ED for openSIS 8.0.
Currently, there is no known workaround for CVE-2021-40636. It is recommended to apply the official patch or update.
More information about CVE-2021-40636 can be found in the official GitHub issue: https://github.com/OS4ED/openSIS-Classic/issues/198