SQL injection vulnerability exists in OS4ED openSIS...
Critical severity
Unreviewed
Published
Nov 8, 2024
to the GitHub Advisory Database
•
Updated Jul 17, 2025
Description
Published by the National Vulnerability Database
Nov 8, 2024
Published to the GitHub Advisory Database
Nov 8, 2024
Last updated
Jul 17, 2025
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.
References