First published: Mon Feb 13 2023(Updated: )
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-45962 is medium with a CVSS score of 6.5.
SQL Injection is a type of attack that allows an attacker to manipulate a database by injecting malicious SQL code.
CVE-2022-45962 allows an attacker to perform SQL Injection in openSIS Community Edition v8.0 and earlier via CalendarModal.php.
To fix CVE-2022-45962, it is recommended to upgrade to a patched version of openSIS Community Edition.
You can find more information about CVE-2022-45962 at the following references: [CCAT Gitbook](https://ccat.gitbook.io/cyber-sec/cve/cve-2022-45962-postauth-sqli), [OS4ED GitHub Repository](https://github.com/OS4ED/openSIS-Classic), and [CalendarModal.php (line 30)](https://github.com/OS4ED/openSIS-Classic/blob/381a1ad907285182c88e30b8bb6ce91123d9275d/CalendarModal.php#L30).