CVE-2025-22925: SQL Injection
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22925?
CVE-2025-22925 is classified as a high severity SQL injection vulnerability that could allow an authenticated admin attacker to execute unauthorized queries.
How do I fix CVE-2025-22925?
To fix CVE-2025-22925, you should update OS4ED openSIS to version 9.2 or later where the vulnerability has been patched.
What is the impact of CVE-2025-22925?
The impact of CVE-2025-22925 includes unauthorized access to sensitive data and potential manipulation of the database by exploiting SQL injection.
Who is affected by CVE-2025-22925?
CVE-2025-22925 affects users of OS4ED openSIS versions 7.0 to 9.1 who have admin access.
Can CVE-2025-22925 be exploited remotely?
Yes, CVE-2025-22925 can be exploited by a remote authenticated attacker with admin privileges.