SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Jul 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Os4ed
Os4ed opensis |
|
CPEs | cpe:2.3:a:os4ed:opensis:8.0:*:*:*:community:*:*:* cpe:2.3:a:os4ed:opensis:9.1:*:*:*:community:*:*:* |
|
Vendors & Products |
Os4ed
Os4ed opensis |
Wed, 16 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Opensis
Opensis opensis |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:opensis:opensis:*:*:*:*:*:*:*:* | |
Vendors & Products |
Opensis
Opensis opensis |
|
Metrics |
cvssV3_1
|
Wed, 16 Oct 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. |
Tue, 15 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-10-15T00:00:00
Updated: 2024-10-16T19:59:12.665Z
Reserved: 2024-05-17T00:00:00
Link: CVE-2024-35584

Updated: 2024-10-16T19:56:38.504Z

Status : Analyzed
Published: 2024-10-15T19:15:16.957
Modified: 2025-07-17T17:33:12.133
Link: CVE-2024-35584

No data.