CVE-2021-41677: SQL Injection
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41677?
CVE-2021-41677 is a SQL injection vulnerability in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
What is the severity of CVE-2021-41677?
CVE-2021-41677 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
How does CVE-2021-41677 affect openSIS?
CVE-2021-41677 allows an attacker to issue SQL commands through the /opensis/functions/GetStuListFnc.php &Grade= parameter, potentially leading to unauthorized access or manipulation of the application database.
Which software versions are affected by CVE-2021-41677?
Version 8.0 of openSIS is affected by CVE-2021-41677 when MySQL or MariaDB is used as the application database.
Is there a fix for CVE-2021-41677?
Yes, OS4Ed has released a fix for CVE-2021-41677. It is recommended to update to the latest version of openSIS to mitigate the risk.