SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Opensis
Opensis opensis |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:opensis:opensis:*:*:*:*:*:*:*:* | |
Vendors & Products |
Opensis
Opensis opensis |
|
Metrics |
cvssV3_1
|
Wed, 16 Oct 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. |
Tue, 15 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-10-15T00:00:00
Updated: 2024-10-16T19:59:12.665Z
Reserved: 2024-05-17T00:00:00
Link: CVE-2024-35584

Updated: 2024-10-16T19:56:38.504Z

Status : Awaiting Analysis
Published: 2024-10-15T19:15:16.957
Modified: 2024-10-16T20:35:10.897
Link: CVE-2024-35584

No data.