CVE-2021-41691
os4ed opensis Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2021-41691 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 26, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 25, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Open Source Information System CommunityBrowse OS4Ed / Open Source Information System Community | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHopenSIS Student Information System 8.0 SQL Injection
openSIS Student Information System version 8.0 is susceptible to SQL injection via the student_id and TRANSFER[SCHOOL] parameters in POST request sent to /TransferredOutModal.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.
Remediation
Apply the latest security patch or upgrade to a patched version of openSIS Student Information System to mitigate the SQL Injection vulnerability (CVE-2021-41691).
Source: ProjectDiscovery