CVE-2024-51211

CRITICAL EXPLOITED NUCLEI

OS4ED openSIS-Classic 9.1 - SQL Injection via resetuserinfo.php $username_stn_id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-51211 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository claims an unauthenticated SQL injection in openSIS-Classic 9.1 but provides no actual exploit code, only placeholder images and a vague description. The author states they will 'explain the PoC code when I hear back from the manufacturer,' which is a red flag for incomplete or deceptive content.

Description

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

Exploits (1)

vulncheck_xdb SUSPICIOUS
infoleak
https://github.com/kutsa1/My-CVE

The repository claims an unauthenticated SQL injection in openSIS-Classic 9.1 but provides no actual exploit code, only placeholder images and a vague description. The author states they will 'explain the PoC code when I hear back from the manufacturer,' which is a red flag for incomplete or deceptive content.

Classification
Suspicious 90%
Attack Type
Sqli
Complexity
Theoretical
Reliability
Theoretical
Target: openSIS-Classic 9.1 and 9.0
No auth needed
Prerequisites: network access to the target application
devstral-2 · analyzed Feb 25, 2026 Full analysis →

Nuclei Templates (1)

openSIS Classic v9.1 - SQL Injection
CRITICALVERIFIEDby Haliteroglu
Shodan: title:"openSIS"
FOFA: title="openSIS"

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0406
EPSS Percentile 88.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2024-12-05
CWE
CWE-89
Status published
Products (2)
os4ed/opensis 9.0
os4ed/opensis 9.1
Published Nov 08, 2024
Tracked Since Feb 18, 2026