Record summary

CVE-2024-51211 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 21, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

VulnCheck, CVE List9.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALopenSIS Classic v9.1 - SQL InjectionCVSS 9.8

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

Impact

Attackers can exploit this vulnerability to compromise system security and integrity.

Remediation

Apply the latest security patches and updates to address this vulnerability.

WeaknessesCWE-89
AuthorsHaliteroglu
Template tagscvecve2024sqliopensistime-based-sqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: title:"openSIS"
FOFA: title="openSIS"

Source: ProjectDiscovery

References

2