Known Vulnerabilities for products from Open-school
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Open-school".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-14754 json | Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter. | 9.8 - CRITICAL | 2019-08-08 | 2019-08-14 |
| CVE-2019-14696 json | Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. | 6.1 - MEDIUM | 2019-08-06 | 2019-08-13 |
| CVE-2014-9127 json | Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenti... | 6.5 - MEDIUM | 2020-02-08 | 2020-02-10 |
| CVE-2014-9126 json | Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to inject arb... | 6.1 - MEDIUM | 2020-02-08 | 2020-02-10 |
| CVE-2009-4208 json | SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL co... | Not Provided | 2009-12-04 | 2026-04-23 |
Known software with vulnerabilities from Open-school
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Open-school | Open-school | 2.2 |