CVE-2026-103116 | OS4ED openSIS-Classic up to 9.3 Student List Search Endpoint GetStuListFnc.php DBQuery LO_sort sql injection (Issue 476)

SecurityVulns

A vulnerability was found in OS4ED openSIS-Classic up to 9.3. It has been classified as critical. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection.

This vulnerability is handled as CVE-2026-103116. The attack can be initiated remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More