Description
A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-30
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection via the General Information Tab allows remote attackers to execute arbitrary SQL queries on the database, potentially exposing, altering, or deleting student data
Action: Patch
AI Analysis

Impact

A flaw exists in the save action of Student.php within the General Information Tab of OS4ED openSIS-Classic. The function fails to properly sanitize the 'students' argument, permitting attackers to inject SQL when they manipulate this parameter. This injection can be performed remotely and allows unauthorized reading, modification, or deletion of student records. The vulnerability maps to CWE-74 (Improper Neutralization of Input) and CWE‑89 (SQL Injection).

Affected Systems

The flaw affects OS4ED openSIS-Classic releases up to and including version 9.3. All deployments that have not applied an update to these versions are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. The exploit is publicly disclosed, and the EPSS score is not available, implying that publicly available information does not quantify exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the vulnerable endpoint over the network by submitting crafted parameters to the save action; no special privileges on the client side are required. The impact is limited to the scope of the affected database, but the exposed data may be sensitive. Overall risk is moderate but warrants timely remediation.

Generated by OpenCVE AI on September 30, 2026 at 11:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest openSIS‑Classic release that contains the fix for the SQL injection flaw as soon as a patch is released by the vendor.
  • Apply input validation or sanitation on the server side for the 'students' parameter, ensuring that all database queries use parameterized statements or prepared statements to prevent injection.
  • Restrict access to the General Information Tab and the save action to authorized users only, and monitor authentication and database access logs for anomalous activity.

Generated by OpenCVE AI on September 30, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Title OS4ED openSIS-Classic General Information Tab Student.php save action sql injection
First Time appeared Os4ed
Os4ed opensis-classic
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:os4ed:opensis-classic:*:*:*:*:*:*:*:*
Vendors & Products Os4ed
Os4ed opensis-classic
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Os4ed Opensis-classic
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T16:49:07.541Z

Reserved: 2026-09-30T05:51:30.595Z

Link: CVE-2026-103113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T11:16:43.330

Modified: 2026-09-30T14:04:38.183

Link: CVE-2026-103113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T11:30:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')