5189 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-6131
OS4ED Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassScheduleSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-27226
OpenClinic Web Database
6.4
MEDIUM
EPSS
1.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6145
ERPNext Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6136
OS4Ed Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6125
OS4Ed Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the GetSchool.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6130
OS4ED Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassDropSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-27242
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27245
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27229
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findPersonID parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6123
OS4Ed Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email parameter in the page EmailCheck.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27238
OpenClinic Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27243
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoService parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6129
OS4ED Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page CpSessionSet.php is vulnerable to SQL injection.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-27239
OpenClinic Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6128
OS4Ed Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. The meet_date parameter in the page CoursePeriodModal.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6119
OS4Ed Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The byear parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27246
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6135
OS4Ed Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the Validator.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6124
OS4Ed Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email parameter in the page EmailCheckOthers.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27244
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoCode parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.