Записи OS4ED
81 опубликованных записей вендора os4ed.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 4 · 4,9 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')54
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-96 Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')2
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-284 Improper Access Control1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
81 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2020-13381Готовый эксплойт | openSIS through 7.4 allows SQL Injection.os4ed · opensis · CWE-89 | Критическая9,8 | — | 59,0 % | 1 июл. 2020 г. |
52В плане | CVE-2020-13382Готовый эксплойт | openSIS through 7.4 has Incorrect Access Control.os4ed · opensis · CWE-306 | Критическая9,1 | — | 52,8 % | 1 июл. 2020 г. |
50В плане | CVE-2020-13383Готовый эксплойт | openSIS through 7.4 allows Directory Traversal.os4ed · opensis · CWE-22 | Высокая7,5 | — | 67,8 % | 1 июл. 2020 г. |
46В плане | CVE-2021-39378Proof of concept | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.os4ed · opensis · CWE-89 | Критическая9,8 | — | 22,7 % | 1 сент. 2021 г. |
45В плане | CVE-2020-6637Proof of concept | openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.os4ed · opensis · CWE-89 | Критическая9,8 | — | 20,1 % | 24 авг. 2020 г. |
42В плане | CVE-2020-6142Эксплойта нет | A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-22 | Критическая9,8 | — | 9,2 % | 1 сент. 2020 г. |
41В плане | CVE-2020-6144Эксплойта нет | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Критическая9,8 | — | 6,2 % | 1 сент. 2020 г. |
41В плане | CVE-2020-6143Эксплойта нет | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Критическая9,8 | — | 6,2 % | 1 сент. 2020 г. |
41В плане | CVE-2021-40617Proof of concept | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.os4ed · opensis · CWE-89 | Критическая9,8 | — | 5,2 % | 11 окт. 2021 г. |
40В плане | CVE-2020-6141Эксплойта нет | An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Критическая9,8 | — | 3,9 % | 1 сент. 2020 г. |
40В плане | CVE-2021-39379Proof of concept | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.os4ed · opensis · CWE-89 | Критическая9,8 | — | 3,7 % | 1 сент. 2021 г. |
40В плане | CVE-2021-39377Proof of concept | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.os4ed · opensis · CWE-89 | Критическая9,8 | — | 3,6 % | 1 сент. 2021 г. |
40В плане | CVE-2021-40353Proof of concept | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.os4ed · opensis · CWE-89 | Критическая9,8 | — | 2,9 % | 31 авг. 2021 г. |
40В плане | CVE-2020-6140Эксплойта нет | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Критическая9,8 | — | 2,6 % | 1 сент. 2020 г. |
40В плане | CVE-2020-6137Эксплойта нет | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Критическая9,8 | — | 2,6 % | 1 сент. 2020 г. |
40В плане | CVE-2020-6138Эксплойта нет | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Критическая9,8 | — | 2,6 % | 1 сент. 2020 г. |
40В плане | CVE-2020-6139Эксплойта нет | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Критическая9,8 | — | 2,6 % | 1 сент. 2020 г. |
40В плане | CVE-2020-13380Эксплойта нет | openSIS before 7.4 allows SQL Injection.os4ed · opensis · CWE-89 | Критическая9,8 | — | 2,4 % | 1 июл. 2020 г. |
40В плане | CVE-2024-51211Proof of concept | SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file.os4ed · opensis · CWE-89 | Критическая9,8 | — | 2,3 % | 8 нояб. 2024 г. |
40В плане | CVE-2021-27341Эксплойта нет | OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameos4ed · opensis · CWE-22 | Критическая9,8 | — | 2,1 % | 16 сент. 2021 г. |
40В плане | CVE-2021-41691Proof of concept | A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" paraos4ed · opensis · CWE-89 | Критическая9,8 | — | 1,9 % | 24 июн. 2025 г. |
39Наблюдать | CVE-2021-40618Эксплойта нет | An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONTos4ed · opensis · CWE-89 | Критическая9,8 | — | 1,4 % | 12 окт. 2021 г. |
39Наблюдать | CVE-2021-41677Эксплойта нет | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.os4ed · opensis · CWE-89 | Критическая9,8 | — | 1,3 % | 30 нояб. 2021 г. |
39Наблюдать | CVE-2021-41678Эксплойта нет | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.os4ed · opensis · CWE-89 | Критическая9,8 | — | 1,3 % | 30 нояб. 2021 г. |
39Наблюдать | CVE-2021-41679Эксплойта нет | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.os4ed · opensis · CWE-89 | Критическая9,8 | — | 1,3 % | 30 нояб. 2021 г. |
- CVE-2020-1338157В плане
openSIS through 7.4 allows SQL Injection.
КритическаяCVSS 9,8Готовый эксплойтEPSS 59 %os4ed · opensis1 июл. 2020 г.
- CVE-2020-1338252В плане
openSIS through 7.4 has Incorrect Access Control.
КритическаяCVSS 9,1Готовый эксплойтEPSS 53 %os4ed · opensis1 июл. 2020 г.
- CVE-2020-1338350В плане
openSIS through 7.4 allows Directory Traversal.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 68 %os4ed · opensis1 июл. 2020 г.
- CVE-2021-3937846В плане
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
КритическаяCVSS 9,8Proof of conceptEPSS 23 %os4ed · opensis1 сент. 2021 г.
- CVE-2020-663745В плане
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
КритическаяCVSS 9,8Proof of conceptEPSS 20 %os4ed · opensis24 авг. 2020 г.
- CVE-2020-614242В плане
A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %os4ed · opensis1 сент. 2020 г.
- CVE-2020-614441В плане
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %os4ed · opensis1 сент. 2020 г.
- CVE-2020-614341В плане
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %os4ed · opensis1 сент. 2020 г.
- CVE-2021-4061741В плане
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %os4ed · opensis11 окт. 2021 г.
- CVE-2020-614140В плане
An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %os4ed · opensis1 сент. 2020 г.
- CVE-2021-3937940В плане
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %os4ed · opensis1 сент. 2021 г.
- CVE-2021-3937740В плане
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %os4ed · opensis1 сент. 2021 г.
- CVE-2021-4035340В плане
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %os4ed · opensis31 авг. 2021 г.
- CVE-2020-614040В плане
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %os4ed · opensis1 сент. 2020 г.
- CVE-2020-613740В плане
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %os4ed · opensis1 сент. 2020 г.
- CVE-2020-613840В плане
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %os4ed · opensis1 сент. 2020 г.
- CVE-2020-613940В плане
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %os4ed · opensis1 сент. 2020 г.
- CVE-2020-1338040В плане
openSIS before 7.4 allows SQL Injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %os4ed · opensis1 июл. 2020 г.
- CVE-2024-5121140В плане
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %os4ed · opensis8 нояб. 2024 г.
- CVE-2021-2734140В плане
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parame
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %os4ed · opensis16 сент. 2021 г.
- CVE-2021-4169140В плане
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" para
КритическаяCVSS 9,8Proof of conceptEPSS 2 %os4ed · opensis24 июн. 2025 г.
- CVE-2021-4061839Наблюдать
An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONT
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %os4ed · opensis12 окт. 2021 г.
- CVE-2021-4167739Наблюдать
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %os4ed · opensis30 нояб. 2021 г.
- CVE-2021-4167839Наблюдать
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %os4ed · opensis30 нояб. 2021 г.
- CVE-2021-4167939Наблюдать
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %os4ed · opensis30 нояб. 2021 г.