Lucene search

K
cveMitreCVE-2022-45962
HistoryFeb 13, 2023 - 9:15 p.m.

CVE-2022-45962

2023-02-1321:15:13
CWE-89
mitre
web.nvd.nist.gov
21
cve
2022
45962
open solutions
education
inc
opensis
community edition
sql injection
calendarmodal.php
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

7

Confidence

High

EPSS

0.002

Percentile

58.3%

Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.

Affected configurations

Nvd
Node
os4edopensisRange8.0community
VendorProductVersionCPE
os4edopensis*cpe:2.3:a:os4ed:opensis:*:*:*:*:community:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

7

Confidence

High

EPSS

0.002

Percentile

58.3%

Related for CVE-2022-45962