A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.
An attacker sends a malicious HTTP POST request to the /TransferredOutModal.php endpoint, injecting unsafe SQL expressions in the 'student_id' and 'TRANSFER[SCHOOL]' parameters. User-supplied data is not properly validated or parameterized before being passed to the database query. This allows modification of the logic of SQL queries executed by the application, leading to unauthorized access or data manipulation in the database.
An attacker can obtain unauthorized read, modification, or deletion of data from the system's database, including sensitive student and employee data. Depending on the database server configuration, it is also possible to execute system commands or gain complete control over the application.
Apply patches available from the manufacturer according to references. Additionally, it is recommended to restrict network access to the /TransferredOutModal.php endpoint at the firewall or WAF level and monitor application logs for suspicious POST requests to this resource.
OS4Ed OpenSIS Community v8.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOs4ed Opensis
APPOs4Ed8.0
Related vulnerabilities
SQL Injection w Os4Ed openSIS — parametr filter_id
SQL Injection w OS4ED openSIS — parametr cp_id w module wiadomości
Path traversal w openSIS — nieautoryzowany dostęp do plików przez Modules.php
Path traversal w openSIS umożliwia nieautoryzowany dostęp do plików
SQL injection w OS4Ed openSIS via parametr groupid w Group.php