CVE-2020-27409: OS4ED Opensis
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
Affected products
- OS4ED Opensis: before 7.5 (fixed in 7.5)
Published 2020-12-04. Last modified 2026-06-17.