Description
A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Patch Software
AI Analysis

Impact

The vulnerability originates from improper handling of the cust argument in the Student Search component’s CustomFieldsFnc.php file, leading to both generic SQL injection (CWE-74) and specific SQL injection (CWE-89) when the argument is manipulated. An attacker can inject arbitrary SQL statements that the application passes directly to the database, potentially exfiltrating sensitive data such as student records, or altering or deleting information, thereby compromising confidentiality, integrity, and availability of the system. The exploit is remote, meaning it can be launched over the network without needing local access to the system.

Affected Systems

The flaw affects the OS4ED openSIS-Classic application version 9.3 and earlier. Organizations running the Student Search functionality within this open-source school management system are susceptible until a new release or patch is applied.

Risk and Exploitability

The assigned CVSS score of 5.3 indicates a moderate severity, yet the public release of an exploit script has already been observed, raising the practical risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but the remote nature of the attack coupled with the lack of a vendor response increases the urgency. Without a vendor patch, the risk remains high enough to warrant immediate action.

Generated by OpenCVE AI on September 30, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify if a newer release of OS4ED openSIS-Classic that fixes the flaw is available and upgrade the system to that version.
  • If no update is available, modify CustomFieldsFnc.php to replace the unsanitized cust input with parameterized queries or proper input validation to prevent SQL injection.
  • Configure the database account used by the application with the least privileges required, preferably read‑only if the functionality permits, to limit potential damage from a successful injection.

Generated by OpenCVE AI on September 30, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection
First Time appeared Os4ed
Os4ed opensis-classic
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:os4ed:opensis-classic:*:*:*:*:*:*:*:*
Vendors & Products Os4ed
Os4ed opensis-classic
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Os4ed Opensis-classic
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T12:15:12.251Z

Reserved: 2026-09-30T05:51:37.435Z

Link: CVE-2026-103115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T13:17:17.910

Modified: 2026-09-30T13:17:17.910

Link: CVE-2026-103115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:30:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')