First published: Thu Mar 03 2022(Updated: )
OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40637 is a vulnerability that affects OS4ED openSIS 8.0 and allows for cross-site scripting (XSS) attacks.
CVE-2021-40637 has a severity level of medium with a CVSS score of 6.1.
CVE-2021-40637 allows an attacker to inject JavaScript code through EmailCheckOthers.php in order to obtain the user's cookie and take control of their session.
OpenSIS 8.0 by OS4ED is the only affected software version for CVE-2021-40637.
At the moment, there is no official fix available for CVE-2021-40637, but it is recommended to follow the GitHub issue provided for any updates or patches.