SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Opensis
Opensis opensis |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:opensis:opensis:*:*:*:*:*:*:*:* | |
Vendors & Products |
Opensis
Opensis opensis |
|
Metrics |
cvssV3_1
|
Wed, 16 Oct 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. |
Tue, 15 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-15T00:00:00
Updated: 2024-10-16T19:59:12.665Z
Reserved: 2024-05-17T00:00:00
Link: CVE-2024-35584
Vulnrichment
Updated: 2024-10-16T19:56:38.504Z
NVD
Status : Awaiting Analysis
Published: 2024-10-15T19:15:16.957
Modified: 2024-10-16T20:35:10.897
Link: CVE-2024-35584
Redhat
No data.