CVE-2021-41677
EUVD-2021-2868930.11.2021, 13:15
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| os4ed | opensis | 8.0 |
𝑥
= Vulnerable software versions