SQL Injection Vulnerability in OS4ED openSIS Software
CVE-2025-22929
9.8CRITICAL
What is CVE-2025-22929?
OpenSIS versions 7.0 through 9.1 are affected by a SQL injection vulnerability through the filter_id parameter in the StudentFilters.php script. This vulnerability can allow an attacker to manipulate and execute arbitrary SQL queries on the database, potentially leading to sensitive data exposure and unauthorized access. Organizations using affected versions are advised to implement security measures to mitigate this risk and ensure the integrity of their data.
