CVE-2024-51211
OS4ED openSIS-Classic SQL Injection Vulnerability
Record summary
CVE-2024-51211 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 5, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 21, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
openSIS-ClassicBrowse OS4ED / openSIS-ClassicDefault status: unknown | VulnCheck, CVE List | 9.1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALopenSIS Classic v9.1 - SQL InjectionCVSS 9.8
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.
Impact
Attackers can exploit this vulnerability to compromise system security and integrity.
Remediation
Apply the latest security patches and updates to address this vulnerability.
Source: ProjectDiscovery