CVE-2025-22924: SQL Injection
Published Apr 2, 2025
·Updated
OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stuid parameter at /modules/students/Student.php.
Affected Software
2 affected components
OS4ED openSIS>=7.0<=9.1
OS4ED openSIS>=7.0<=9.1
Event History
Apr 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22924?
CVE-2025-22924 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2025-22924?
To fix CVE-2025-22924, sanitize and validate user input for the stu_id parameter in the affected versions of OS4ED openSIS.
3
Which versions of OS4ED openSIS are affected by CVE-2025-22924?
OS4ED openSIS versions 7.0 through 9.1 are vulnerable to CVE-2025-22924.
4
What type of vulnerability is CVE-2025-22924?
CVE-2025-22924 is a SQL injection vulnerability that can allow attackers to manipulate database queries.
5
How can I identify if my system is vulnerable to CVE-2025-22924?
To identify if your system is vulnerable to CVE-2025-22924, check if you are using OS4ED openSIS version 7.0 to 9.1 and test the stu_id parameter for injection vulnerabilities.