CVE-2026-103114 | OS4ED openSIS-Classic up to 9.3 Assignment Management Endpoint Assignments.php DBQuery_assignment Tables sql injection (Issue 474)
A vulnerability has been found in OS4ED openSIS-Classic up to 9.3 and classified as critical. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the argument Tables leads to sql injection.
This vulnerability is traded as CVE-2026-103114. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More