Known Vulnerabilities for products from Os4ed
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Os4ed".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-38885 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-11-20 | 2023-11-30 |
| CVE-2023-38884 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-11-20 | 2023-11-30 |
| CVE-2023-38883 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-11-20 | 2023-11-30 |
| CVE-2023-38882 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-11-20 | 2023-11-30 |
| CVE-2023-38881 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-11-20 | 2023-11-30 |
| CVE-2022-45962 json | Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal... | 6.5 - MEDIUM | 2023-02-13 | 2023-02-22 |
| CVE-2022-27041 json | Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject... | 7.5 - HIGH | 2022-04-11 | 2022-04-15 |
| CVE-2021-41679 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2021-11-30 | 2021-11-30 |
| CVE-2021-41678 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2021-11-30 | 2021-11-30 |
| CVE-2021-41677 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2021-11-30 | 2021-11-30 |
| CVE-2021-40651 json | OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which c... | 6.5 - MEDIUM | 2021-09-29 | 2021-10-07 |
| CVE-2021-40637 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-03-03 | 2022-03-09 |
| CVE-2021-40636 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2022-03-03 | 2022-03-09 |
| CVE-2021-40635 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2022-03-03 | 2022-03-09 |
| CVE-2021-40618 json | An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN ... | 9.8 - CRITICAL | 2021-10-12 | 2021-10-19 |
| CVE-2021-40617 json | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. | 9.8 - CRITICAL | 2021-10-11 | 2021-10-19 |
| CVE-2021-40543 json | Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two p... | 9.8 - CRITICAL | 2021-10-11 | 2021-10-18 |
| CVE-2021-40542 json | Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScr... | 6.1 - MEDIUM | 2021-10-11 | 2021-10-18 |
| CVE-2021-40353 json | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An ... | 9.8 - CRITICAL | 2021-09-01 | 2021-09-09 |
| CVE-2021-40310 json | OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via... | 5.4 - MEDIUM | 2021-09-24 | 2021-09-30 |
Known software with vulnerabilities from Os4ed
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Os4ed | Opensis | 4.5 |