PULSE
FEED
ransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Services
← All CVEs
CVE WatchSep 30, 2026

CVE-2026-103113

A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/stud

CVSS

4.7

Medium

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-74 · CWE-89

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-972938.5 HIG
—
———Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.4h
CVE-2026-972878.5 HIG
—
———Contributor SQL Injection in Event Tickets <= 5.29.5 versions.4h
CVE-2026-968287.6 HIG
—
———Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.4h
CVE-2026-968277.6 HIG
—
———Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.4h
CVE-2026-968229.3 CRI
—
———Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.4h
CVE-2026-963467.6 HIG
—
———Author SQL Injection in WP ERP <= 1.17.9 versions.4h