Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | OS4ED openSIS-Classic Save Data DatabaseInc.php db_properties sql injection | |
| First Time appeared |
Os4ed
Os4ed opensis-classic |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:os4ed:opensis-classic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Os4ed
Os4ed opensis-classic |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-30T13:41:37.987Z
Reserved: 2026-09-30T05:51:44.225Z
Link: CVE-2026-103117
Updated: 2026-09-30T13:41:34.454Z
Status : Deferred
Published: 2026-09-30T13:17:18.280
Modified: 2026-09-30T14:17:27.157
Link: CVE-2026-103117
No data.
OpenCVE Enrichment
No data.