A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.
References
Link | Resource |
---|---|
https://www.opensis.com/download/english | Product |
https://github.com/5qu1n7/CVE-2021-40353 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-08-31 18:15
Updated : 2021-09-08 17:52
NVD link : CVE-2021-40353
Mitre link : CVE-2021-40353
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
os4ed
- opensis