First published: Tue Nov 30 2021(Updated: )
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =8.0 | |
=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41677 is a SQL injection vulnerability in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
CVE-2021-41677 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
CVE-2021-41677 allows an attacker to issue SQL commands through the /opensis/functions/GetStuListFnc.php &Grade= parameter, potentially leading to unauthorized access or manipulation of the application database.
Version 8.0 of openSIS is affected by CVE-2021-41677 when MySQL or MariaDB is used as the application database.
Yes, OS4Ed has released a fix for CVE-2021-41677. It is recommended to update to the latest version of openSIS to mitigate the risk.