Impact
A flaw exists in the save action of Student.php within the General Information Tab of OS4ED openSIS-Classic. The function fails to properly sanitize the 'students' argument, permitting attackers to inject SQL when they manipulate this parameter. This injection can be performed remotely and allows unauthorized reading, modification, or deletion of student records. The vulnerability maps to CWE-74 (Improper Neutralization of Input) and CWE‑89 (SQL Injection).
Affected Systems
The flaw affects OS4ED openSIS-Classic releases up to and including version 9.3. All deployments that have not applied an update to these versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The exploit is publicly disclosed, and the EPSS score is not available, implying that publicly available information does not quantify exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the vulnerable endpoint over the network by submitting crafted parameters to the save action; no special privileges on the client side are required. The impact is limited to the scope of the affected database, but the exposed data may be sensitive. Overall risk is moderate but warrants timely remediation.
OpenCVE Enrichment