github.com
https://github.com/d0ub1edd/CVE-Reference/blob/main/CVE-2024-46626.md CVE-2024-46626
HIGH
openSIS 9.1 - SQLi (Authenticated)
Record summary
CVE-2024-46626 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 2, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
opensisBrowse os4ed / opensisDefault status: unknown | CVE List | 9.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBopenSIS 9.1 - SQLi (Authenticated)ExploitDB exploitby Devrim DıragumandanNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-46626