CVE-2025-22930: SQL Injection
Published Apr 3, 2025
·Updated
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.
Affected Software
2 affected components
OS4ED openSIS>=7.0<=9.1
OS4ED openSIS>=7.0<=9.1
Event History
Apr 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22930?
CVE-2025-22930 is classified as a critical SQL injection vulnerability that can lead to unauthorized data access in OS4ED openSIS.
2
How do I fix CVE-2025-22930?
To fix CVE-2025-22930, update your OS4ED openSIS installation to a version later than v9.1.
3
What are the potential impacts of CVE-2025-22930?
The potential impacts of CVE-2025-22930 include unauthorized database access, data leakage, and potentially compromising user data.
4
Which versions of OS4ED openSIS are affected by CVE-2025-22930?
CVE-2025-22930 affects OS4ED openSIS versions from 7.0 to 9.1.
5
Where can I find more information about CVE-2025-22930?
Detailed information about CVE-2025-22930 can be found in the official OS4ED openSIS repository on GitHub.