SQL Injection Vulnerability in OpenSIS Classic by OS4ED
CVE-2022-27041
7.5HIGH
What is CVE-2022-27041?
The OpenSIS Classic 8.0 application is susceptible to an SQL injection vulnerability due to insufficient input validation in the 'student_id' parameter of the 'Student.php' module. This flaw can be exploited by attackers to inject malicious SQL queries, enabling them to retrieve sensitive information from the application’s database. Such exploitation raises serious concerns about the confidentiality and integrity of data, necessitating immediate remediation to secure the application against unauthorized database access.
