cinzinga.com
https://cinzinga.com/CVE-2020-6637 CVE-2020-6637
CRITICALNuclei
OpenSIS 7.3 - SQL Injection
Record summary
CVE-2020-6637 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALOpenSIS 7.3 - SQL InjectionCVSS 9.8
OpenSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.
Remediation
Apply the latest security patch or upgrade to a patched version of OpenSIS.
WeaknessesCWE-89
Authorspikpikcu
Template tagscvecve2020sqliopensisos4edvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:os4ed:opensis:7.3:*:*:*:community:*:*:*
Shodan: http.title:"openSIS"
Shodan: http.title:"opensis"
FOFA: title="opensis"
Google: intitle:"opensis"
https://cinzinga.com/CVE-2020-6637/ https://nvd.nist.gov/vuln/detail/CVE-2020-6637 https://sourceforge.net/projects/opensis-ce/files/ https://github.com/OS4ED/openSIS-Responsive-Design/commit/1127ae0bb7c3a2883febeabc6b71ad8d73510de8 https://opensis.com/
Source: ProjectDiscovery
References
5github.com
https://github.com/OS4ED/openSIS-Responsive-Design/commit/1127ae0bb7c3a2883febeabc6b71ad8d73510de8 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-6637 opensis.com
https://opensis.com/ sourceforge.net
https://sourceforge.net/projects/opensis-ce/files