CVE-2026-103115: SQL Injection in OS4ED openSIS-Classic
A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
AI Analysis
Technical Summary
This vulnerability in OS4ED openSIS-Classic up to version 9.3 allows remote attackers to inject SQL commands via the 'cust' parameter in the Student Search component's functions/CustomFieldsFnc.php file. The flaw permits unauthorized database queries or modifications. The vulnerability is confirmed public with an exploit released, but no vendor response or patch is currently available.
Potential Impact
Successful exploitation could allow an attacker with network access to the affected system to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification. The vulnerability requires low attack complexity and no user interaction, but does require low privileges. The overall impact is limited by the vulnerability's vector and privileges required but remains a significant risk due to remote exploitability and public exploit availability.
Mitigation Recommendations
No official fix or patch has been released by the vendor yet. Users should monitor the vendor's advisories for updates. Until a patch is available, consider restricting network access to the affected component and applying web application firewall rules to detect and block SQL injection attempts targeting the 'cust' parameter.
CVE-2026-103115: SQL Injection in OS4ED openSIS-Classic
Description
A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS v4.0
Score 5.3medium
Affected software
OS4ED
openSIS-Classic
cpe:2.3:a:os4ed:opensis-classic:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in OS4ED openSIS-Classic up to version 9.3 allows remote attackers to inject SQL commands via the 'cust' parameter in the Student Search component's functions/CustomFieldsFnc.php file. The flaw permits unauthorized database queries or modifications. The vulnerability is confirmed public with an exploit released, but no vendor response or patch is currently available.
Potential Impact
Successful exploitation could allow an attacker with network access to the affected system to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification. The vulnerability requires low attack complexity and no user interaction, but does require low privileges. The overall impact is limited by the vulnerability's vector and privileges required but remains a significant risk due to remote exploitability and public exploit availability.
Mitigation Recommendations
No official fix or patch has been released by the vendor yet. Users should monitor the vendor's advisories for updates. Until a patch is available, consider restricting network access to the affected component and applying web application firewall rules to detect and block SQL injection attempts targeting the 'cust' parameter.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-30T05:51:37.435Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abd07622a4e24523d03fb27
Added to database: 09/30/2026, 12:58:10 UTC
Last enriched: 09/30/2026, 13:03:29 UTC
Last updated: 09/30/2026, 14:40:25 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.