CVE-2025-65594: High severity openSIS openSIS vulnerability
Published Dec 9, 2025
·Updated
OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users.
Affected Software
2 affected components
openSIS openSIS<=9.2
OS4ED openSIS<=9.2
Event History
Dec 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65594?
CVE-2025-65594 has a high severity rating due to its potential for unauthorized database write operations.
2
How do I fix CVE-2025-65594?
To fix CVE-2025-65594, update OpenSIS to version 9.3 or later, which addresses the access control vulnerability.
3
Who is affected by CVE-2025-65594?
CVE-2025-65594 affects users of OpenSIS version 9.2 and below.
4
What type of vulnerability is CVE-2025-65594?
CVE-2025-65594 is categorized as an Incorrect Access Control vulnerability.
5
Can CVE-2025-65594 be exploited without authentication?
No, CVE-2025-65594 requires an authenticated low-privilege user to exploit the vulnerability.