CVE-2026-103117
Received Received - Intake

SQL Injection in OS4ED openSIS-Classic

Vulnerability report for CVE-2026-103117, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
os4ed opensis_classic to 9.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected SQL injection vulnerability in OS4ED openSIS-Classic up to version 9.3. The issue occurs in the student data save form where the application uses unvalidated user input to construct SQL queries. Specifically, the POST form field values[] is iterated over, and each first-level array key is used as a table name without validation. This table name is passed directly into the db_properties() function, which concatenates it into a SHOW COLUMNS FROM <table> SQL statement. Attackers can inject malicious SQL code into the table name, enabling conditional queries against any database table.

Detection Guidance

To detect this SQL injection vulnerability, monitor for unusual database queries or errors in the openSIS-Classic application logs. Check for POST requests to modules/students/Student.php with values[] array keys containing SQL syntax like time delays (e.g., sleep(4)) or conditional statements. Use tools like sqlmap to test for blind SQL injection by sending crafted payloads to the vulnerable endpoint.

Impact Analysis

An attacker can exploit this vulnerability to perform time-based or boolean blind SQL injection. This allows them to read arbitrary database content, test row counts against conditions, and infer sensitive information. The attack can be executed remotely with a single request and does not require the payload to be stored. Any account with access to the student data save page, including administrators, can exploit this issue using the application's database credentials.

Compliance Impact

This vulnerability can lead to unauthorized access to sensitive data, which may violate compliance requirements such as GDPR (data protection) and HIPAA (health information privacy). Unauthorized data exposure or modification could result in legal penalties, reputational damage, and loss of trust. Organizations using affected versions must address this issue to maintain compliance.

Mitigation Strategies

Immediately restrict access to the student data save form in openSIS-Classic to trusted users only. Apply input validation by whitelisting allowed table names for the values[] array keys. Replace direct SQL query concatenation in functions/DatabaseInc.php with parameterized queries or quoted identifiers. Monitor for exploitation attempts and update to a patched version once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103117. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart