← Back

Open School

open-school

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Open School
open-school

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open School
1Open School
Nov 21, 2024
Feb 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index....Show more
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index.php.Show less
1Open School
1Open School
Nov 21, 2024
Feb 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to inject arbitrary web script or HTML via the YII_CSRF_TOKEN HTTP cookie or the StudentDocument, StudentCat...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to inject arbitrary web script or HTML via the YII_CSRF_TOKEN HTTP cookie or the StudentDocument, StudentCategories, StudentPreviousDatas parameters to index.php.Show less
1Open School
1Open School
Jun 17, 2026
Aug 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.
1Open School
1Open School
Jun 17, 2026
Aug 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
1Open School
1Open School
Apr 23, 2026
Dec 4, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to index.php.