Record summary

CVE-2020-6637 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALOpenSIS 7.3 - SQL InjectionCVSS 9.8

OpenSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.

Remediation

Apply the latest security patch or upgrade to a patched version of OpenSIS.

WeaknessesCWE-89
Authorspikpikcu
Template tagscvecve2020sqliopensisos4edvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:os4ed:opensis:7.3:*:*:*:community:*:*:*
Shodan: http.title:"openSIS"
Shodan: http.title:"opensis"
FOFA: title="opensis"
Google: intitle:"opensis"

Source: ProjectDiscovery

References

5