OS4ED kayıtları
os4ed üreticisine ait 81 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 4 · %4,9
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')54
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-96 Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')2
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-284 Improper Access Control1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
81 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2020-13381Silahlaştırılmış | openSIS through 7.4 allows SQL Injection.os4ed · opensis · CWE-89 | Kritik9,8 | — | %59,0 | 1 Tem 2020 |
52Planlayın | CVE-2020-13382Silahlaştırılmış | openSIS through 7.4 has Incorrect Access Control.os4ed · opensis · CWE-306 | Kritik9,1 | — | %52,8 | 1 Tem 2020 |
50Planlayın | CVE-2020-13383Silahlaştırılmış | openSIS through 7.4 allows Directory Traversal.os4ed · opensis · CWE-22 | Yüksek7,5 | — | %67,8 | 1 Tem 2020 |
46Planlayın | CVE-2021-39378Kavram kanıtı | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.os4ed · opensis · CWE-89 | Kritik9,8 | — | %22,7 | 1 Eyl 2021 |
45Planlayın | CVE-2020-6637Kavram kanıtı | openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.os4ed · opensis · CWE-89 | Kritik9,8 | — | %20,1 | 24 Ağu 2020 |
42Planlayın | CVE-2020-6142İstismar yok | A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-22 | Kritik9,8 | — | %9,2 | 1 Eyl 2020 |
41Planlayın | CVE-2020-6144İstismar yok | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Kritik9,8 | — | %6,2 | 1 Eyl 2020 |
41Planlayın | CVE-2020-6143İstismar yok | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Kritik9,8 | — | %6,2 | 1 Eyl 2020 |
41Planlayın | CVE-2021-40617Kavram kanıtı | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.os4ed · opensis · CWE-89 | Kritik9,8 | — | %5,2 | 11 Eki 2021 |
40Planlayın | CVE-2020-6141İstismar yok | An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Kritik9,8 | — | %3,9 | 1 Eyl 2020 |
40Planlayın | CVE-2021-39379Kavram kanıtı | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.os4ed · opensis · CWE-89 | Kritik9,8 | — | %3,7 | 1 Eyl 2021 |
40Planlayın | CVE-2021-39377Kavram kanıtı | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.os4ed · opensis · CWE-89 | Kritik9,8 | — | %3,6 | 1 Eyl 2021 |
40Planlayın | CVE-2021-40353Kavram kanıtı | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.os4ed · opensis · CWE-89 | Kritik9,8 | — | %2,9 | 31 Ağu 2021 |
40Planlayın | CVE-2020-6140İstismar yok | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Kritik9,8 | — | %2,6 | 1 Eyl 2020 |
40Planlayın | CVE-2020-6137İstismar yok | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Kritik9,8 | — | %2,6 | 1 Eyl 2020 |
40Planlayın | CVE-2020-6138İstismar yok | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Kritik9,8 | — | %2,6 | 1 Eyl 2020 |
40Planlayın | CVE-2020-6139İstismar yok | SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.os4ed · opensis · CWE-89 | Kritik9,8 | — | %2,6 | 1 Eyl 2020 |
40Planlayın | CVE-2020-13380İstismar yok | openSIS before 7.4 allows SQL Injection.os4ed · opensis · CWE-89 | Kritik9,8 | — | %2,4 | 1 Tem 2020 |
40Planlayın | CVE-2024-51211Kavram kanıtı | SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file.os4ed · opensis · CWE-89 | Kritik9,8 | — | %2,3 | 8 Kas 2024 |
40Planlayın | CVE-2021-27341İstismar yok | OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameos4ed · opensis · CWE-22 | Kritik9,8 | — | %2,1 | 16 Eyl 2021 |
40Planlayın | CVE-2021-41691Kavram kanıtı | A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" paraos4ed · opensis · CWE-89 | Kritik9,8 | — | %1,9 | 24 Haz 2025 |
39İzleyin | CVE-2021-40618İstismar yok | An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONTos4ed · opensis · CWE-89 | Kritik9,8 | — | %1,4 | 12 Eki 2021 |
39İzleyin | CVE-2021-41677İstismar yok | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.os4ed · opensis · CWE-89 | Kritik9,8 | — | %1,3 | 30 Kas 2021 |
39İzleyin | CVE-2021-41678İstismar yok | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.os4ed · opensis · CWE-89 | Kritik9,8 | — | %1,3 | 30 Kas 2021 |
39İzleyin | CVE-2021-41679İstismar yok | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.os4ed · opensis · CWE-89 | Kritik9,8 | — | %1,3 | 30 Kas 2021 |
- CVE-2020-1338157Planlayın
openSIS through 7.4 allows SQL Injection.
KritikCVSS 9,8SilahlaştırılmışEPSS %59os4ed · opensis1 Tem 2020
- CVE-2020-1338252Planlayın
openSIS through 7.4 has Incorrect Access Control.
KritikCVSS 9,1SilahlaştırılmışEPSS %53os4ed · opensis1 Tem 2020
- CVE-2020-1338350Planlayın
openSIS through 7.4 allows Directory Traversal.
YüksekCVSS 7,5SilahlaştırılmışEPSS %68os4ed · opensis1 Tem 2020
- CVE-2021-3937846Planlayın
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
KritikCVSS 9,8Kavram kanıtıEPSS %23os4ed · opensis1 Eyl 2021
- CVE-2020-663745Planlayın
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
KritikCVSS 9,8Kavram kanıtıEPSS %20os4ed · opensis24 Ağu 2020
- CVE-2020-614242Planlayın
A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3.
KritikCVSS 9,8İstismar yokEPSS %9os4ed · opensis1 Eyl 2020
- CVE-2020-614441Planlayın
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
KritikCVSS 9,8İstismar yokEPSS %6os4ed · opensis1 Eyl 2020
- CVE-2020-614341Planlayın
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
KritikCVSS 9,8İstismar yokEPSS %6os4ed · opensis1 Eyl 2020
- CVE-2021-4061741Planlayın
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
KritikCVSS 9,8Kavram kanıtıEPSS %5os4ed · opensis11 Eki 2021
- CVE-2020-614140Planlayın
An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3.
KritikCVSS 9,8İstismar yokEPSS %4os4ed · opensis1 Eyl 2020
- CVE-2021-3937940Planlayın
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
KritikCVSS 9,8Kavram kanıtıEPSS %4os4ed · opensis1 Eyl 2021
- CVE-2021-3937740Planlayın
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.
KritikCVSS 9,8Kavram kanıtıEPSS %4os4ed · opensis1 Eyl 2021
- CVE-2021-4035340Planlayın
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
KritikCVSS 9,8Kavram kanıtıEPSS %3os4ed · opensis31 Ağu 2021
- CVE-2020-614040Planlayın
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.
KritikCVSS 9,8İstismar yokEPSS %3os4ed · opensis1 Eyl 2020
- CVE-2020-613740Planlayın
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.
KritikCVSS 9,8İstismar yokEPSS %3os4ed · opensis1 Eyl 2020
- CVE-2020-613840Planlayın
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.
KritikCVSS 9,8İstismar yokEPSS %3os4ed · opensis1 Eyl 2020
- CVE-2020-613940Planlayın
SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3.
KritikCVSS 9,8İstismar yokEPSS %3os4ed · opensis1 Eyl 2020
- CVE-2020-1338040Planlayın
openSIS before 7.4 allows SQL Injection.
KritikCVSS 9,8İstismar yokEPSS %2os4ed · opensis1 Tem 2020
- CVE-2024-5121140Planlayın
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file.
KritikCVSS 9,8Kavram kanıtıEPSS %2os4ed · opensis8 Kas 2024
- CVE-2021-2734140Planlayın
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parame
KritikCVSS 9,8İstismar yokEPSS %2os4ed · opensis16 Eyl 2021
- CVE-2021-4169140Planlayın
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" para
KritikCVSS 9,8Kavram kanıtıEPSS %2os4ed · opensis24 Haz 2025
- CVE-2021-4061839İzleyin
An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONT
KritikCVSS 9,8İstismar yokEPSS %1os4ed · opensis12 Eki 2021
- CVE-2021-4167739İzleyin
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
KritikCVSS 9,8İstismar yokEPSS %1os4ed · opensis30 Kas 2021
- CVE-2021-4167839İzleyin
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
KritikCVSS 9,8İstismar yokEPSS %1os4ed · opensis30 Kas 2021
- CVE-2021-4167939İzleyin
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database.
KritikCVSS 9,8İstismar yokEPSS %1os4ed · opensis30 Kas 2021