openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
References
Link | Resource |
---|---|
https://cinzinga.com/CVE-2020-6637/ | Exploit Technical Description Third Party Advisory |
https://github.com/OS4ED/openSIS-Responsive-Design/commit/1127ae0bb7c3a2883febeabc6b71ad8d73510de8 | Patch Third Party Advisory |
https://opensis.com/ | Product |
https://sourceforge.net/projects/opensis-ce/files/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-08-24T19:01:32
Updated: 2020-08-24T19:01:32
Reserved: 2020-01-09T00:00:00
Link: CVE-2020-6637
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-08-24T19:15:10.620
Modified: 2020-09-03T12:05:56.997
Link: CVE-2020-6637
JSON object: View
Redhat Information
No data.
CWE