Sceawere
Vulnerability Detail
CVE-2026-103117UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
openSIS-Classic SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 3h ago
- Vendor
- OS4ED
- Product
- openSIS-Classic
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-09-30T13:17:18.280Z",
"pubdate": "2026-09-30T13:17:18.280Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in OS4ED openSIS-Classic versions up to 9.3. The vulnerability resides within the db_properties function located in functions/DatabaseInc.php.\nThis flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying database. Successful exploitation permits unauthorized access to, modification of, or deletion of sensitive educational data stored within the system.\nThe vulnerability is categorized as a SQL injection (SQLi) issue, stemming from improper sanitization of input passed to the Save Data Handler component. Given that the exploit vector is publicly available and the vendor has not yet responded to disclosure reports, the risk profile is considered high.\nAttackers can leverage this vulnerability to bypass authentication, extract credentials, exfiltrate private student or administrative records, and potentially achieve full database compromise, which may lead to remote code execution depending on the database configuration and permissions.",
"technicalDetails": "The vulnerability is located in the db_properties function within functions/DatabaseInc.php, which serves as a core component of the Save Data Handler in openSIS-Classic. The root cause is the insecure handling of user-supplied input that is concatenated directly into SQL query strings without sufficient parameterization or escaping.\nSpecifically, the application fails to enforce strict input validation or use prepared statements when processing argument values intended for database interactions. An attacker can manipulate these argument values by injecting malicious SQL fragments. Since the application fails to treat these values as data, the database engine interprets the injected strings as executable SQL commands.\nThe attack flow is initiated by sending a crafted remote request to the vulnerable endpoint. When the application invokes db_properties, the manipulated input alters the logic of the intended SQL query. For instance, an attacker could terminate the original query using a quote character and append arbitrary commands using SQL syntax such as UNION SELECT, stacked queries, or blind SQL injection techniques.\nBecause the function is reachable remotely, no prior authentication is strictly required if the exposed interface is accessible. The scope of the attack allows the adversary to interact with any tables defined within the database schema. Post-exploitation impact includes the systematic exfiltration of sensitive information, such as PII (Personally Identifiable Information), user accounts, and passwords. Furthermore, if the database user possesses elevated privileges, attackers may be able to interact with the file system or execute system commands through database-specific features like 'INTO OUTFILE' or similar functionality.\nAffected versions include all openSIS-Classic iterations up to 9.3. The lack of parameterized queries or a robust Object-Relational Mapping (ORM) layer within this specific function confirms a systemic failure in the input handling architecture of the Save Data Handler."
}