CyberRota Analysis
AI analysis pending.
CVE
CVE-2020-6131
Severity
HIGH
CVSS
8.8
EPSS
1.40%
Original NVD Description
SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassScheduleSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.