SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Os4ed
Os4ed opensis |
|
| CPEs | cpe:2.3:a:os4ed:opensis:8.0:*:*:*:community:*:*:* cpe:2.3:a:os4ed:opensis:9.1:*:*:*:community:*:*:* |
|
| Vendors & Products |
Os4ed
Os4ed opensis |
Wed, 16 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensis
Opensis opensis |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:opensis:opensis:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensis
Opensis opensis |
|
| Metrics |
cvssV3_1
|
Wed, 16 Oct 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. |
Tue, 15 Oct 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-15T00:00:00
Updated: 2024-10-16T19:59:12.665Z
Reserved: 2024-05-17T00:00:00
Link: CVE-2024-35584
Updated: 2024-10-16T19:56:38.504Z
Status : Analyzed
Published: 2024-10-15T19:15:16.957
Modified: 2025-07-17T17:33:12.133
Link: CVE-2024-35584
No data.