CRITICAL🇵🇱 Wersja polska

CVE-2021-41691

CVSS 9.8v3.1pub. 2025-06-24upd. 2025-07-09

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.

🤖 AI Analysis
How it works

An attacker sends a malicious HTTP POST request to the /TransferredOutModal.php endpoint, injecting unsafe SQL expressions in the 'student_id' and 'TRANSFER[SCHOOL]' parameters. User-supplied data is not properly validated or parameterized before being passed to the database query. This allows modification of the logic of SQL queries executed by the application, leading to unauthorized access or data manipulation in the database.

Impact

An attacker can obtain unauthorized read, modification, or deletion of data from the system's database, including sensitive student and employee data. Depending on the database server configuration, it is also possible to execute system commands or gain complete control over the application.

Mitigation & patch

Apply patches available from the manufacturer according to references. Additionally, it is recommended to restrict network access to the /TransferredOutModal.php endpoint at the firewall or WAF level and monitor application logs for suspicious POST requests to this resource.

Who is affected

OS4Ed OpenSIS Community v8.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Os4ed Opensis

    APP
    Os4Ed
    8.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-22929CRITICAL9.8PL ✓same product

SQL Injection w Os4Ed openSIS — parametr filter_id

CVE-2025-22928CRITICAL9.8PL ✓same product

SQL Injection w OS4ED openSIS — parametr cp_id w module wiadomości

CVE-2025-22927CRITICAL9.1PL ✓same product

Path traversal w openSIS — nieautoryzowany dostęp do plików przez Modules.php

CVE-2025-22926CRITICAL9.8PL ✓same product

Path traversal w openSIS umożliwia nieautoryzowany dostęp do plików

CVE-2025-22930CRITICAL9.8PL ✓same product

SQL injection w OS4Ed openSIS via parametr groupid w Group.php