PULSE
FEED
ransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Services
← Todos los CVEs
CVE Watch30 sept 2026

CVE-2026-103116

A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php

CVSS

6.3

Medio

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 30 sept 2026 · Última mod.: 30 sept 2026 · CWE-74 · CWE-89

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-972938.5 ALT
—
———Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.4h
CVE-2026-972878.5 ALT
—
———Contributor SQL Injection in Event Tickets <= 5.29.5 versions.4h
CVE-2026-968287.6 ALT
—
———Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.4h
CVE-2026-968277.6 ALT
—
———Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.4h
CVE-2026-968229.3 CRÍ
—
———Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.4h
CVE-2026-963467.6 ALT
—
———Author SQL Injection in WP ERP <= 1.17.9 versions.4h