openSIS-Classic vulnerabilities
CVEs whose affected-version data names the openSIS-Classic package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-103115Medium· 6.3OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection
A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql inje…
CVE-2026-103116Medium· 6.3OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection
A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes …
CVE-2026-103114Medium· 6.3A vulnerability was identified in OS4ED openSIS-Classic up to 9.3
A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of th…
CVE-2026-103113Medium· 4.7A vulnerability was determined in OS4ED openSIS-Classic up to 9.3
A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argume…