Sceawere
Vulnerability Detail
CVE-2026-103114UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
openSIS-Classic SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 4h ago
- Vendor
- OS4ED
- Product
- openSIS-Classic
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the argument Tables leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-30T12:17:12.457Z",
"pubdate": "2026-09-30T12:17:12.457Z",
"executiveSummary": "A critical SQL injection (SQLi) vulnerability has been identified in the openSIS-Classic student information system, affecting all versions up to 9.3.\nThe vulnerability resides in the Assignment Management component, specifically within the DBQuery_assignment function located in modules/grades/Assignments.php.\nAn unauthenticated or authenticated remote attacker can exploit this flaw by supplying malicious input via the 'Tables' argument to execute arbitrary SQL commands against the underlying database.\nSuccessful exploitation allows an attacker to bypass authentication, access sensitive information, modify database records, or potentially gain full control over the application's data layer.\nDue to the public availability of exploit code and the lack of a vendor-provided patch, this vulnerability presents a high risk to deployments of openSIS-Classic.\nImmediate defensive measures, such as input validation and implementation of Web Application Firewalls (WAF), are required to prevent exploitation.",
"technicalDetails": "The vulnerability is a classic SQL injection flaw occurring in the modules/grades/Assignments.php file of openSIS-Classic. The root cause is the improper neutralization of user-supplied data within the 'Tables' argument before it is processed by the DBQuery_assignment function.\nIn the affected component, the application accepts the 'Tables' parameter and concatenates it directly into a dynamic SQL query string without adequate sanitization, parameterization, or the use of prepared statements. This failure allows an attacker to inject arbitrary SQL syntax, thereby altering the intended logic of the database query executed by the application.\nThe attack flow begins with the attacker crafting a malicious HTTP request targeting the assignment management endpoint. By injecting payload strings containing SQL keywords such as UNION, SELECT, or sleep() functions into the 'Tables' argument, the attacker can manipulate the query structure.\nBecause the function processes this input unsafely, the database management system (DBMS) interprets the malicious injection as part of the authorized command. This permits unauthorized execution of queries, which can be leveraged for data exfiltration (e.g., dumping user credentials or student records) or administrative command execution depending on the database user permissions.\nThe vulnerability is remotely exploitable over a network connection, requiring no physical access to the server. Given the nature of the flaw, it does not strictly require advanced authentication, depending on the implementation of the entry point, significantly lowering the barrier to entry for potential attackers.\nPublic exploit vectors exist that automate the discovery and exploitation of this vulnerability. Post-exploitation impact is severe, as the attacker can perform unauthorized read/write/delete operations on the application backend. This could lead to a complete compromise of the confidentiality, integrity, and availability of the student data managed by the system. Given that the project has been notified and has not yet addressed the issue, any system running version 9.3 or earlier remains actively vulnerable to these remote attacks."
}