📦 Opensis

by Os4ed

🔍 What is Opensis?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-41691

CRITICAL CVSS 9.8 Jun 24, 2025

This SQL injection vulnerability in OS4Ed OpenSIS allows attackers to execute arbitrary SQL commands through manipulated student_id and TRANSFER{SCHOOL] parameters. It affects all users of OpenSIS Com...

CVE-2025-22926

CRITICAL CVSS 9.8 Apr 3, 2025

This vulnerability allows attackers to perform directory traversal attacks by sending a specially crafted POST request to the openSIS messaging module. Attackers can potentially read, write, or delete...

CVE-2025-22930

CRITICAL CVSS 9.8 Apr 3, 2025

This SQL injection vulnerability in OS4ED openSIS allows attackers to execute arbitrary SQL commands via the groupid parameter in the Group.php messaging component. All organizations running openSIS v...

CVE-2025-22927

CRITICAL CVSS 9.1 Apr 3, 2025

This vulnerability allows attackers to perform directory traversal attacks by sending a specially crafted POST request to the openSIS messaging module. Attackers can potentially read, write, or delete...

CVE-2024-51211

CRITICAL CVSS 9.8 Nov 8, 2024

This SQL injection vulnerability in OS4ED openSIS-Classic allows attackers to execute arbitrary SQL commands by manipulating the $username_stn_id parameter in resetuserinfo.php. Successful exploitatio...

CVE-2023-38880

CRITICAL CVSS 9.8 Nov 20, 2023

This vulnerability allows unauthenticated attackers to download full database backups containing sensitive information like password hashes. It affects OS4ED's openSIS Classic Community Edition versio...

CVE-2021-41678

CRITICAL CVSS 9.8 Nov 30, 2021

A SQL injection vulnerability in openSIS version 8.0 allows attackers to execute arbitrary SQL commands through the staff[TITLE] parameter in Staff.php. This affects all openSIS deployments using MySQ...

CVE-2021-41677

CRITICAL CVSS 9.8 Nov 30, 2021

A SQL injection vulnerability in openSIS version 8.0 allows attackers to execute arbitrary SQL commands through the Grade parameter. This affects all openSIS 8.0 installations using MySQL or MariaDB d...

CVE-2021-40618

CRITICAL CVSS 9.8 Oct 12, 2021

This SQL injection vulnerability in openSIS Classic 8.0 allows attackers to execute arbitrary SQL commands through specific parameters in HoldAddressFields.php. This affects all users running the vuln...

CVE-2021-40543

CRITICAL CVSS 9.8 Oct 11, 2021

This vulnerability allows attackers to execute arbitrary SQL commands on Opensis-Classic Version 8.0 by injecting malicious input into the 'usrid' and 'prof_id' parameters in PasswordCheck.php. It aff...

CVE-2021-27341

CRITICAL CVSS 9.8 Sep 16, 2021

OpenSIS Community Edition versions up to 7.6 contain a local file inclusion vulnerability in DownloadWindow.php via the 'filename' parameter. This allows attackers to read arbitrary files from the ser...

CVE-2021-39377

CRITICAL CVSS 9.8 Sep 1, 2021

This SQL injection vulnerability in openSIS 8.0 allows attackers to execute arbitrary SQL commands through the username parameter in index.php when using MySQL/MariaDB. This can lead to unauthorized d...

CVE-2021-39379

CRITICAL CVSS 9.8 Sep 1, 2021

This SQL injection vulnerability in openSIS 8.0 allows attackers to execute arbitrary SQL commands on the MySQL/MariaDB database through the password_stn_id parameter in ResetUserInfo.php. Any openSIS...

CVE-2021-40353

CRITICAL CVSS 9.8 Sep 1, 2021

This is a critical SQL injection vulnerability in openSIS version 8.0 when using MySQL or MariaDB databases. Attackers can inject malicious SQL commands through the USERNAME parameter in index.php, po...

CVE-2020-6143

CRITICAL CVSS 9.8 Sep 1, 2020

This is a critical remote code execution vulnerability in OS4Ed openSIS 7.4's installation functionality. Attackers can inject malicious PHP code through the password parameter during installation, al...

CVE-2020-6138

CRITICAL CVSS 9.8 Sep 1, 2020

This CVE describes a critical SQL injection vulnerability in OS4Ed openSIS 7.3's password reset functionality. Attackers can exploit the 'uname' parameter in ResetUserInfo.php to execute arbitrary SQL...

CVE-2020-6140

CRITICAL CVSS 9.8 Sep 1, 2020

This SQL injection vulnerability in OS4Ed openSIS 7.3 allows attackers to execute arbitrary SQL commands through the password reset functionality. Attackers can potentially access, modify, or delete d...

CVE-2020-6141

CRITICAL CVSS 9.8 Sep 1, 2020

CVE-2020-6141 is a critical SQL injection vulnerability in OS4Ed openSIS 7.3 login functionality that allows attackers to execute arbitrary SQL commands. This affects all openSIS 7.3 installations wit...

CVE-2025-65594

HIGH CVSS 8.1 Dec 9, 2025

OpenSIS 9.2 and below contains an incorrect access control vulnerability in Student.php that allows authenticated low-privilege users to perform unauthorized database write operations on other users' ...

CVE-2025-26186

HIGH CVSS 8.1 Jul 15, 2025

This SQL injection vulnerability in openSIS v9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in Ajax.php. Attackers can potentially read, modify, or delete database ...

CVE-2025-22924

HIGH CVSS 8.8 Apr 2, 2025

CVE-2025-22924 is a SQL injection vulnerability in OS4ED openSIS versions 7.0 through 9.1 that allows attackers to execute arbitrary SQL commands via the stu_id parameter in the Student.php module. Th...

CVE-2023-38884

HIGH CVSS 7.5 Nov 20, 2023

An unauthenticated attacker can access any student's files by manipulating the URL path in openSIS Classic Community Edition. This affects all installations of version 9.0 that expose the student file...

CVE-2022-27041

HIGH CVSS 7.5 Apr 11, 2022

CVE-2022-27041 is an SQL injection vulnerability in OpenSIS Classic's Student.php module that allows attackers to manipulate the student_id parameter to execute arbitrary SQL queries. This affects all...

CVE-2021-40635

HIGH CVSS 7.5 Mar 3, 2022

CVE-2021-40635 is an SQL injection vulnerability in OS4ED openSIS 8.0 that allows attackers to execute arbitrary SQL queries through ChooseCpSearch.php and ChooseRequestSearch.php. This affects all or...