Description
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
References (3)
Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/OS4ED/openSIS-Responsive-Design/commit/edca0855e7bc27d5b28dcb2d16f057ada865e282#diff-5f88e2ce4cd96451df7580911120b4b2
Third Party Advisory x_refsource_misc
https://github.com/OS4ED/openSIS-Responsive-Design/compare/ver7.4...V7.5
Third Party Advisory x_refsource_misc
https://insinuator.net/2020/10/opensis-vulnerabilities/
Scores
CVSS v3
6.1
EPSS
0.0042
EPSS Percentile
61.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
os4ed/opensis
< 7.5
Published
Dec 04, 2020
Tracked Since
Feb 18, 2026