← Back to browse · API

CVE-2020-6140

Severity
CRITICAL
CVSS
9.8
EPSS
0.02634
Risk score
40.12
CISA KEV
No
PoC
No
Published
2020-09-01
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2020-27294, GHSA-WWGG-2C86-7H3Q
Products
n/a:OS4ED OS4Ed openSIS 7.3
Sources
euvd EUVD-2020-27294

Description

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email parameter in the password reset page /opensis/ResetUserInfo.php is vulnerable to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

References