Os4ed
Os4ed Opensis: vulnerabilidades y CVE
Os4ed Opensis tiene 81 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 31 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE81
Últimos 12 meses2
Críticas31
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-11944 | Media (5.3) | 0.48% | — | 14 jul 2026 | openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server… |
| CVE-2025-65594 | Alta (8.1) | 0.29% | — | 9 dic 2025 | OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users. |
| CVE-2025-26186 | Alta (8.1) | 0.46% | — | 15 jul 2025 | SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php |
| CVE-2021-41691 | Crítica (9.8) | 1.9% | — | 24 jun 2025 | A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php. |
| CVE-2025-22931 | Alta (7.5) | 0.47% | — | 3 abr 2025 | An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members. |
| CVE-2025-22930 | Crítica (9.8) | 0.52% | — | 3 abr 2025 | OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php. |
| CVE-2025-22929 | Crítica (9.8) | 0.52% | — | 3 abr 2025 | OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php. |
| CVE-2025-22926 | Crítica (9.8) | 0.90% | — | 3 abr 2025 | An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename. |
| CVE-2025-22928 | Crítica (9.8) | 0.42% | — | 3 abr 2025 | OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php. |
| CVE-2025-22927 | Crítica (9.1) | 0.77% | — | 3 abr 2025 | An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename. |
| CVE-2025-22925 | Alta (7.5) | 0.45% | — | 2 abr 2025 | OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully… |
| CVE-2025-22924 | Alta (8.8) | 0.40% | — | 2 abr 2025 | OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php. |
| CVE-2025-22923 | Alta (8.8) | 0.85% | — | 2 abr 2025 | An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile. |
| CVE-2024-51211 | Crítica (9.8) | 2.3% | — | 8 nov 2024 | SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be… |
| CVE-2024-35584 | Alta (8.8) | 5.9% | — | 15 oct 2024 | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible… |
| CVE-2024-46626 | Alta (8.8) | 0.88% | — | 2 oct 2024 | OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload. |
| CVE-2023-38885 | Alta (8.8) | 0.36% | — | 20 nov 2023 | OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state… |
| CVE-2023-38884 | Alta (7.5) | 0.88% | — | 20 nov 2023 | An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting… |
| CVE-2023-38883 | Media (6.1) | 0.63% | — | 20 nov 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a… |
| CVE-2023-38882 | Media (6.1) | 0.63% | — | 20 nov 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a… |
| CVE-2023-38881 | Media (6.1) | 0.62% | — | 20 nov 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a… |
| CVE-2023-38880 | Crítica (9.8) | 0.96% | — | 20 nov 2023 | The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever an admin generates a database backup, the backup is stored in the web… |
| CVE-2023-38879 | Alta (7.5) | 3.6% | — | 20 nov 2023 | The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'. |
| CVE-2022-45962 | Media (6.5) | 0.90% | — | 13 feb 2023 | Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php. |
| CVE-2022-27041 | Alta (7.5) | 1.3% | — | 11 abr 2022 | Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases. |
| CVE-2021-40637 | Media (6.1) | 0.79% | — | 3 mar 2022 | OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user. |
| CVE-2021-40636 | Alta (7.5) | 1.3% | — | 3 mar 2022 | OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database. |
| CVE-2021-40635 | Alta (7.5) | 1.3% | — | 3 mar 2022 | OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database. |
| CVE-2021-41679 | Crítica (9.8) | 1.3% | — | 30 nov 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the… |
| CVE-2021-41678 | Crítica (9.8) | 1.3% | — | 30 nov 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.