CVE-2020-6124: OS4ED Opensis
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email parameter in the page EmailCheckOthers.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected products
- OS4ED Opensis: version 7.3 only
Published 2020-09-01. Last modified 2026-06-17.