SQL Injection Vulnerability in OS4ED openSIS-Classic Database Management
CVE-2026-103117
Key Information:
- Vendor
Os4ed
- Status
- Vendor
- CVE Published:
- 30 September 2026
Badges
What is CVE-2026-103117?
A security vulnerability identified in OS4ED openSIS-Classic affects the 'db_properties' function within the 'DatabaseInc.php' file of the Save Data Handler component. This vulnerability arises from improper handling of argument values, allowing for SQL injection attacks that can be executed remotely. Despite early notification of the issue through an issue report, the project has not yet provided a response. As the exploit has been publicly disclosed, immediate attention is required to mitigate potential security risks to users of the affected versions.
Affected Version(s)
openSIS-Classic 9.0
openSIS-Classic 9.1
openSIS-Classic 9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
