SQL Injection Vulnerability in OpenSIS Classic by OS4ED
CVE-2022-27041
7.5HIGH
What is CVE-2022-27041?
The OpenSIS Classic 8.0 application is susceptible to an SQL injection vulnerability due to insufficient input validation in the 'student_id' parameter of the 'Student.php' module. This flaw can be exploited by attackers to inject malicious SQL queries, enabling them to retrieve sensitive information from the application’s database. Such exploitation raises serious concerns about the confidentiality and integrity of data, necessitating immediate remediation to secure the application against unauthorized database access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
