Sceawere
Vulnerability Detail
CVE-2026-103115UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
openSIS-Classic SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 3h ago
- Vendor
- OS4ED
- Product
- openSIS-Classic
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-30T13:17:17.910Z",
"pubdate": "2026-09-30T13:17:17.910Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in OS4ED openSIS-Classic, affecting all versions up to and including 9.3. The flaw exists within the Student Search component, specifically inside the functions/CustomFieldsFnc.php file.\nThe vulnerability arises due to improper neutralization of the 'cust' argument, which allows an unauthenticated or authenticated remote attacker to inject arbitrary SQL commands. This flaw permits unauthorized access to the underlying database, potentially leading to the compromise of sensitive student records, administrative credentials, or full application takeover.\nBecause the exploit is publicly available and the vendor has not provided a patch despite early disclosure, the risk to operational environments is high. Attackers can remotely execute malicious queries to bypass authentication mechanisms, exfiltrate confidential data, or modify system integrity. Immediate defensive measures are required to isolate the affected functionality or implement external security filtering to prevent exploitation.",
"technicalDetails": "The vulnerability resides in the handling of the 'cust' parameter within functions/CustomFieldsFnc.php. The application fails to perform adequate input validation or parameterization before concatenating user-supplied data into database queries.\nThe attack flow commences when an attacker submits a crafted HTTP request containing a malicious payload in the 'cust' argument to the Student Search interface. By appending SQL syntax—such as UNION-based or blind SQL injection payloads—the attacker manipulates the logical structure of the backend database query.\nSince the application processes these inputs without proper sanitization, the injected SQL commands are executed by the database management system with the privileges of the application's database user. This effectively bypasses intended query constraints and allows the attacker to retrieve data from arbitrary tables, perform data manipulation (DML), or, depending on database configuration, potentially execute system-level operations or extract schema metadata.\nThe component affected is the Student Search module. The vulnerability is exploitable remotely over the network, requiring no specific user interaction or elevated privileges depending on the specific endpoint configuration of the openSIS-Classic deployment. The lack of parameterized queries or prepared statements at the source code level within functions/CustomFieldsFnc.php serves as the root cause of this injection flaw.\nPost-exploitation, an attacker can perform a wide array of malicious activities including, but not limited to: exfiltration of Personal Identifiable Information (PII) regarding students, dumping user account hashes for offline cracking, or modifying database records to escalate administrative privileges. The public availability of the exploit code significantly reduces the barrier to entry for adversaries, increasing the likelihood of automated or manual scanning and exploitation attempts against exposed instances of openSIS-Classic version 9.3 and earlier."
}