CVE-2020-27409: OS4ED Opensis

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.

Affected products

  • OS4ED Opensis: before 7.5 (fixed in 7.5)

Published 2020-12-04. Last modified 2026-06-17.