PULSE
FEED
ransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Services
← Todos los CVEs
CVE Watch30 sept 2026

CVE-2026-103115

A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsF

CVSS

6.3

Medio

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 30 sept 2026 · Última mod.: 30 sept 2026 · CWE-74 · CWE-89

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-972938.5 ALT
—
———Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.4h
CVE-2026-972878.5 ALT
—
———Contributor SQL Injection in Event Tickets <= 5.29.5 versions.4h
CVE-2026-968287.6 ALT
—
———Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.4h
CVE-2026-968277.6 ALT
—
———Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.4h
CVE-2026-968229.3 CRÍ
—
———Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.4h
CVE-2026-963467.6 ALT
—
———Author SQL Injection in WP ERP <= 1.17.9 versions.4h