CVE-2025-26186: SQL Injection
Published Jul 15, 2025
·Updated
SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php
Affected Software
2 affected components
openSIS openSIS
OS4ED openSIS=9.1
Remediation
Patch Available
Event History
Jul 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26186?
CVE-2025-26186 is classified as a critical severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2025-26186?
To fix CVE-2025-26186, update openSIS to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2025-26186 on openSIS?
CVE-2025-26186 allows remote attackers to execute arbitrary code, compromising the integrity and confidentiality of the system.
4
Who is affected by CVE-2025-26186?
Users running openSIS version 9.1 are affected by CVE-2025-26186 due to the vulnerability in Ajax.php.
5
What types of attacks can CVE-2025-26186 facilitate?
CVE-2025-26186 can facilitate SQL injection attacks, enabling attackers to manipulate database queries through the id parameter.