CVE-2021-40353
CRITICALopenSIS 8.0 - SQL Injection
Title source: llmDescription
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0903
EPSS Percentile
92.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
os4ed/opensis
8.0
Published
Sep 01, 2021
Tracked Since
Feb 18, 2026