CVE-2020-35430: Inxedu

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.

Affected products

  • Inxedu Inxedu: version 2.0.6 only

Published 2021-04-29. Last modified 2026-06-17.