CVE-2026-103115 | OS4ED openSIS-Classic up to 9.3 Student Search CustomFieldsFnc.php cust sql injection (Issue 475)

SecurityVulns

A vulnerability was found in OS4ED openSIS-Classic up to 9.3 and classified as critical. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection.

This vulnerability is known as CVE-2026-103115. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More