Skip to main content

Vendor/product archive

os4ed / opensis CVEs

Beta · best-effort

81 CVEs tagged to os4ed / opensis31 Critical, 39 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2025-65594

Published Dec 9, 2025

OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26186

Published Jul 15, 2025

SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41691

Published Jun 24, 2025

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /Transfe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-22931

Published Apr 3, 2025

An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff mem…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22930

Published Apr 3, 2025

OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22929

Published Apr 3, 2025

OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22926

Published Apr 3, 2025

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22928

Published Apr 3, 2025

OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22927

Published Apr 3, 2025

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22925

Published Apr 2, 2025

OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker r…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22924

Published Apr 2, 2025

OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22923

Published Apr 2, 2025

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staf…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-51211

Published Nov 8, 2024

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-35584

Published Oct 15, 2024

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and poss…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46626

Published Oct 2, 2024

OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38885

Published Nov 20, 2023

OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38884

Published Nov 20, 2023

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38883

Published Nov 20, 2023

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38882

Published Nov 20, 2023

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38881

Published Nov 20, 2023

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38880

Published Nov 20, 2023

The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever an admin generates a database…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-38879

Published Nov 20, 2023

The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45962

Published Feb 13, 2023

Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27041

Published Apr 11, 2022

Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 81 CVEsPage 1 of 4