CVE-2026-103117
A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/
CVSS
4.7
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 30 sept 2026 · Última mod.: 30 sept 2026 · CWE-74 · CWE-89
Sin historial EPSS suficiente todavía.
A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-972938.5 ALT—
———Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.4hCVE-2026-972878.5 ALT—
———Contributor SQL Injection in Event Tickets <= 5.29.5 versions.4hCVE-2026-968287.6 ALT—
———Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.4hCVE-2026-968277.6 ALT—
———Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.4hCVE-2026-968229.3 CRÍ—
———Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.4hCVE-2026-963467.6 ALT—
———Author SQL Injection in WP ERP <= 1.17.9 versions.4h