CVE-2024-51211 is a critical SQL injection vulnerability in OS4ED openSIS-Classic Version 9.1, specifically within the resetuserinfo.php file. This flaw stems from insufficient input validation of the $username_stn_id parameter, allowing an unauthenticated attacker to inject arbitrary SQL commands. With a CVSS score of 9.8 (Critical), successful exploitation could lead to complete compromise of confidentiality, integrity, and availability of the affected system. While there is no evidence of active exploitation or KEV listing, a Nuclei template exists, indicating public knowledge of exploit techniques. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:os4ed:opensis:9.0:*:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:os4ed:opensis:9.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.