CVE-2022-45962: SQL Injection
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45962?
The severity of CVE-2022-45962 is medium with a CVSS score of 6.5.
What is SQL Injection?
SQL Injection is a type of attack that allows an attacker to manipulate a database by injecting malicious SQL code.
How does CVE-2022-45962 impact openSIS Community Edition?
CVE-2022-45962 allows an attacker to perform SQL Injection in openSIS Community Edition v8.0 and earlier via CalendarModal.php.
How can I fix CVE-2022-45962?
To fix CVE-2022-45962, it is recommended to upgrade to a patched version of openSIS Community Edition.
Where can I find more information about CVE-2022-45962?
You can find more information about CVE-2022-45962 at the following references: [CCAT Gitbook](https://ccat.gitbook.io/cyber-sec/cve/cve-2022-45962-postauth-sqli), [OS4ED GitHub Repository](https://github.com/OS4ED/openSIS-Classic), and [CalendarModal.php (line 30)](https://github.com/OS4ED/openSIS-Classic/blob/381a1ad907285182c88e30b8bb6ce91123d9275d/CalendarModal.php#L30).