CVE-2020-6637

EUVD-2020-27785
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H