SQL Injection Flaw in openSIS Product by OS4ED
CVE-2021-41678
9.8CRITICAL
What is CVE-2021-41678?
A SQL injection vulnerability is present in version 8.0 of openSIS when using MySQL or MariaDB as the database. This flaw allows an attacker to execute arbitrary SQL commands via the /opensis/modules/users/Staff.php interface, specifically targeting the staff[TITLE] parameter. The exploitation of this vulnerability could lead to unauthorized access to sensitive data, making it crucial for users of openSIS to apply recommended security practices and updates.
