Record summary

CVE-2021-41691 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 26, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Open Source Information System Community

Browse OS4Ed / Open Source Information System Community
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHopenSIS Student Information System 8.0 SQL Injection

openSIS Student Information System version 8.0 is susceptible to SQL injection via the student_id and TRANSFER[SCHOOL] parameters in POST request sent to /TransferredOutModal.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.

Remediation

Apply the latest security patch or upgrade to a patched version of openSIS Student Information System to mitigate the SQL Injection vulnerability (CVE-2021-41691).

AuthorsBartu Utku SARP
Template tagscvecve2021sqliauthedbopensisvkevvuln

Source: ProjectDiscovery

References

4