SQL Injection Vulnerability in openSIS by OS4ED
CVE-2021-41677
9.8CRITICAL
What is CVE-2021-41677?
A SQL injection vulnerability has been identified in openSIS version 8.0 when integrated with MySQL or MariaDB databases. This flaw allows attackers to execute arbitrary SQL commands through the vulnerable /opensis/functions/GetStuListFnc.php &Grade= parameter, potentially compromising the integrity of the database and exposing sensitive information. Organizations using this version of openSIS should prioritize updating their installations to mitigate the risks associated with this vulnerability.
