CVE-2022-27041: SQL Injection
Published Apr 11, 2022
·Updated
Due to lack of protection, parameter studentid in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.
Affected Software
1 affected component
OS4ED openSIS=8.0
Remediation
Patch Available
Event History
Apr 11, 2022
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-27041.
2
What is the severity rating of CVE-2022-27041?
The severity rating of CVE-2022-27041 is high with a value of 7.5.
3
What is the affected software of CVE-2022-27041?
The affected software of CVE-2022-27041 is OpenSIS Classic 8.0.
4
What is the description of CVE-2022-27041?
CVE-2022-27041 is a vulnerability in OpenSIS Classic 8.0 where the lack of protection in the 'student_id' parameter allows for SQL query injection to extract information from databases.
5
Is there a fix for CVE-2022-27041?
Yes, there is a fix available for CVE-2022-27041. It is recommended to update to a patched version of OpenSIS Classic 8.0.