Sceawere

Vulnerability Detail

CVE-2026-103113UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

openSIS-Classic SQL Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
2h ago
Vendor
OS4ED
Product
openSIS-Classic
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-09-30T11:16:43.330Z",
  "pubdate": "2026-09-30T11:16:43.330Z",
  "executiveSummary": "A critical SQL injection (SQLi) vulnerability exists in OS4ED openSIS-Classic up to version 9.3 within the General Information Tab component.\nThe vulnerability resides in the save action of the modules/students/Student.php file, where the application improperly sanitizes the students argument before incorporating it into database queries.\nSuccessful exploitation allows a remote, unauthenticated or authenticated attacker to inject arbitrary SQL commands, potentially leading to unauthorized data exfiltration, modification, or complete database compromise.\nGiven that proof-of-concept exploits are publicly available, the risk of active exploitation is high.\nThe vendor has been notified but has not yet addressed the issue, leaving affected installations vulnerable to exploitation.",
  "technicalDetails": "The root cause of this vulnerability is improper neutralization of special elements used in an SQL command within the modules/students/Student.php file of the openSIS-Classic component. Specifically, the save action function fails to perform adequate input validation or parameterization on the students argument, allowing malicious SQL syntax to be appended to the backend query.\nThe exploitation vector is accessible remotely, meaning an attacker can trigger the vulnerability by sending a specially crafted HTTP request containing malicious SQL payloads targeted at the vulnerable parameter.\nThe attack flow follows a structured pattern: first, the attacker identifies the input vector, in this case, the students argument within the General Information Tab submission process. Second, the attacker crafts a payload designed to manipulate the query logic, typically by injecting characters such as single quotes, semicolons, or commenting characters (e.g., -- or #) to break out of the intended SQL statement context.\nUpon submission, the application's backend database driver processes the tainted input, executing the injected SQL command with the privileges of the database user account connected to the application. This interaction allows the attacker to bypass authentication mechanisms, gain unauthorized read/write access to the database structure, or execute administrative commands.\nAs the application's underlying architecture interacts directly with the database, the impact of this SQL injection is significant. An attacker can perform 'UNION-based' SQLi to extract data from other tables, 'Blind SQLi' to systematically deduce data through response analysis, or potentially 'Stacked Queries' to drop tables or alter system configurations if the database user permissions are overly permissive.\nThis vulnerability affects openSIS-Classic versions up to and including 9.3. The lack of parameterized queries or prepared statements in the affected PHP module is the primary technical failure point, rendering the application susceptible to standard injection techniques."
}
CVE-2026-103113: openSIS-Classic SQL Injection Vulnerability (MEDIUM Severity, CVSS: 4.7) | Sceawere