CVE-2021-41678
30.11.2021, 14:15
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.
Vendor | Product | Version |
---|---|---|
os4ed | opensis | 8.0 |
𝑥
= Vulnerable software versions