Sceawere
Vulnerability Detail
CVE-2026-103116UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
openSIS-Classic SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 3h ago
- Vendor
- OS4ED
- Product
- openSIS-Classic
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-30T13:17:18.090Z",
"pubdate": "2026-09-30T13:17:18.090Z",
"executiveSummary": "A critical SQL injection (SQLi) vulnerability has been identified in OS4ED openSIS-Classic versions up to 9.3.\nThe vulnerability exists within the Student List Search Endpoint, specifically due to improper neutralization of input in the 'LO_sort' parameter.\nThe flaw allows remote, unauthenticated or authenticated attackers to manipulate database queries, potentially leading to unauthorized data extraction, modification, or deletion.\nThis vulnerability poses a significant risk to the confidentiality, integrity, and availability of sensitive student information stored within the openSIS database.\nThe public availability of exploit code increases the risk of active exploitation. The vendor has not yet provided a resolution to the reported issue.",
"technicalDetails": "The vulnerability resides in the function 'DBQuery' located in the file 'functions/GetStuListFnc.php'.\nThe root cause of this SQL injection is the insecure handling of the 'LO_sort' HTTP request argument. The application fails to properly sanitize or parameterize this input before incorporating it directly into a database query execution string.\nThe 'DBQuery' function acts as an intermediary or interface for executing SQL statements against the application's backend database. By supplying a specially crafted payload within the 'LO_sort' parameter, an attacker can manipulate the syntax of the intended SQL statement.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP request (GET or POST, depending on the implementation) to the Student List Search Endpoint. The payload within the 'LO_sort' parameter is processed by 'functions/GetStuListFnc.php' and passed to the 'DBQuery' function without adequate validation or transformation (e.g., escaping or parameterized queries). The database engine interprets the malicious input as part of the SQL command, allowing the attacker to inject arbitrary SQL statements.\nThis vulnerability is remotely exploitable, meaning the attacker does not require physical access to the server. The impact of successful exploitation is high, as it allows for unauthorized interaction with the database. Depending on the database permissions configured for the application's user account, an attacker may be able to dump table contents, bypass authentication mechanisms, modify student records, or, in some configurations, execute administrative operations on the database server.\nAffected versions include all openSIS-Classic iterations up to and including version 9.3. Given that the vulnerability resides in a core search function, it exposes the system to broad reconnaissance and exfiltration attempts."
}