.. / CVE-2021-41691

Exploit for openSIS Student Information System 8.0 SQL Injection (CVE-2021-41691)

Description:

openSIS Student Information System version 8.0 is susceptible to SQL injection via the student_id and TRANSFER[SCHOOL] parameters in POST request sent to /TransferredOutModal.php.

Nuclei Template

View the template here CVE-2021-41691.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-41691.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-41691
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4169
https://www.exploit-db.com/exploits/50637
https://securityforeveryone.com/blog/opensis-student-information-system-0-day-vulnerability-cve-2021-41691