CVE-2021-40636: SQL Injection
Published Mar 3, 2022
·Updated
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
Affected Software
1 affected component
OS4ED openSIS=8.0
Event History
Mar 3, 2022
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-40636?
The severity of CVE-2021-40636 is high with a CVSS score of 7.5.
2
How does CVE-2021-40636 impact OS4ED openSIS 8.0?
CVE-2021-40636 affects OS4ED openSIS 8.0 by allowing SQL injection in CheckDuplicateName.php, which can extract information from the database.
3
How can I fix CVE-2021-40636?
To fix CVE-2021-40636, apply the latest patch or update provided by OS4ED for openSIS 8.0.
4
Is there a workaround for CVE-2021-40636?
Currently, there is no known workaround for CVE-2021-40636. It is recommended to apply the official patch or update.
5
Where can I find more information about CVE-2021-40636?
More information about CVE-2021-40636 can be found in the official GitHub issue: https://github.com/OS4ED/openSIS-Classic/issues/198