ZeroHour

CVE-2020-6132

PoC
CVSS 3.1
8.8 high
EPSS
1%p71
Published
()
Modified
Description

SQL injection vulnerability exists in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page ChooseCP.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vendors
os4ed
Products
opensis
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news