Os4ed CVE 脆弱性と CVE 一覧(80)

製品(CPE): — CVE 件数: 80

Os4ed 脆弱性概要

Os4ed 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには vendor risk sql injection、vendor risk cross-site scripting、パス処理の欠陥, and vendor risk csrf があり、vendor surface software deployment and vendor surface production workloads の利用場面で vendor impact data exposure、ファイル上書き, and vendor impact session compromise などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 120 / 80 CVE 件数
«« 先頭 « 前へ 1 / 4 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-65594 OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users. [email protected] 8.1 0.26% 2025-12-09 2025-12-11
CVE-2025-26186 SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php [email protected] 8.1 0.46% 2025-07-15 2025-07-17
CVE-2021-41691 A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php. [email protected] 9.8 1.72% 2025-06-24 2025-07-09
CVE-2025-22931 An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members. [email protected] 7.5 0.39% 2025-04-03 2025-07-17
CVE-2025-22930 OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php. [email protected] 9.8 0.43% 2025-04-03 2025-04-29
CVE-2025-22929 OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php. [email protected] 9.8 0.43% 2025-04-03 2025-04-29
CVE-2025-22926 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename. [email protected] 9.8 0.88% 2025-04-03 2025-04-30
CVE-2025-22928 OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php. [email protected] 9.8 0.39% 2025-04-03 2025-05-02
CVE-2025-22927 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename. [email protected] 9.1 0.76% 2025-04-03 2025-07-17
CVE-2025-22925 OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability. [email protected] 7.5 0.38% 2025-04-02 2025-04-29
CVE-2025-22924 OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php. [email protected] 8.8 0.33% 2025-04-02 2025-04-29
CVE-2025-22923 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile. [email protected] 8.8 0.82% 2025-04-02 2025-07-17
CVE-2024-51211 SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands. [email protected] 9.8 2.19% 2024-11-08 2025-07-17
CVE-2024-35584 SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. [email protected] 8.8 6.52% 2024-10-15 2025-07-17
CVE-2024-46626 OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload. [email protected] 8.8 0.86% 2024-10-02 2025-07-17
CVE-2023-38885 OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request. [email protected] 8.8 0.36% 2023-11-20 2024-11-21
CVE-2023-38884 An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>' [email protected] 7.5 0.88% 2023-11-20 2024-11-21
CVE-2023-38883 A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'. [email protected] 6.1 0.63% 2023-11-20 2024-11-21
CVE-2023-38882 A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'include' parameter in 'ForExport.php' [email protected] 6.1 0.63% 2023-11-20 2024-11-21
CVE-2023-38881 A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into any of the 'calendar_id', 'school_date', 'month' or 'year' parameters in 'CalendarModal.php'. [email protected] 6.1 0.62% 2023-11-20 2024-11-21
«« 先頭 « 前へ 1 / 4 次へ »
cvelogic Threat Intelligence