Impact
The vulnerability originates from improper handling of the cust argument in the Student Search component’s CustomFieldsFnc.php file, leading to both generic SQL injection (CWE-74) and specific SQL injection (CWE-89) when the argument is manipulated. An attacker can inject arbitrary SQL statements that the application passes directly to the database, potentially exfiltrating sensitive data such as student records, or altering or deleting information, thereby compromising confidentiality, integrity, and availability of the system. The exploit is remote, meaning it can be launched over the network without needing local access to the system.
Affected Systems
The flaw affects the OS4ED openSIS-Classic application version 9.3 and earlier. Organizations running the Student Search functionality within this open-source school management system are susceptible until a new release or patch is applied.
Risk and Exploitability
The assigned CVSS score of 5.3 indicates a moderate severity, yet the public release of an exploit script has already been observed, raising the practical risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but the remote nature of the attack coupled with the lack of a vendor response increases the urgency. Without a vendor patch, the risk remains high enough to warrant immediate action.
OpenCVE Enrichment