First published: Tue Nov 30 2021(Updated: )
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =8.0 | |
=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41678 is a SQL injection vulnerability in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
CVE-2021-41678 allows an attacker to issue SQL commands through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.
CVE-2021-41678 has a severity score of 9.8 out of 10, making it a critical vulnerability.
Version 8.0 of openSIS is affected by CVE-2021-41678.
To fix CVE-2021-41678, update openSIS to a version that has the vulnerability patched. Please refer to the official documentation or vendor website for the patch.