CVE-2026-103117Medium· 4.7▾ TwilightPoC availableA security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values lead…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 25.9 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103114Medium· 6.3A vulnerability was identified in OS4ED openSIS-Classic up to 9.3
CVE-2026-103115Medium· 6.3A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3
CVE-2026-103116Medium· 6.3A weakness has been identified in OS4ED openSIS-Classic up to 9.3
CVE-2026-103113Medium· 4.7A vulnerability was determined in OS4ED openSIS-Classic up to 9.3
CVE-2026-102912Medium· 4.7A vulnerability was identified in SourceCodester Online Leave Management System 1.0
CVE-2026-102909High· 7.3A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0