Description
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'include' parameter in 'ForExport.php'
References (3)
Core 3
Core References
Release Notes
https://github.com/OS4ED/openSIS-Classic
Product
https://www.os4ed.com/
Scores
CVSS v3
6.1
EPSS
0.0017
EPSS Percentile
37.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
os4ed/opensis
9.0
Published
Nov 20, 2023
Tracked Since
Feb 18, 2026