peter bassill · operator
$ cve CVE-2020-6141 JSON

CVE-2020-6141

9.8
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.94% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2020-09-01
Last modified2026-06-17

Affected (1)

VendorProduct
os4edopensis

References

→ the Explorer  ·  watch your stack  ·  NVD