SQL Injection Vulnerability in OS4ED openSIS Software
CVE-2025-22928
9.8CRITICAL
What is CVE-2025-22928?
The OS4ED openSIS software versions 7.0 through 9.1 contain a SQL injection vulnerability that can be exploited through the cp_id parameter located in /modules/messages/Inbox.php. This flaw can allow attackers to manipulate database queries, potentially leading to unauthorized access to sensitive information. Organizations using these versions of openSIS should prioritize patching to safeguard their data integrity and prevent exploitation.
