Skip to main content
Vulnerability Database/CVE-2026-103113

CVE-2026-103113: openSIS-Classic SQL Injection Vulnerability

CVE-2026-103113 is a SQL injection vulnerability in openSIS-Classic affecting versions up to 9.3 through the Student.php module. Attackers can exploit this remotely via the students parameter. This article covers technical details, affected versions, potential impact, and recommended mitigation strategies.

Published:

CVE-2026-103113 Overview

CVE-2026-103113 is a SQL injection vulnerability in OS4ED openSIS-Classic through version 9.3. The flaw resides in the save action of modules/students/Student.php within the General Information Tab component. Attackers can manipulate the students argument to inject arbitrary SQL statements against the backend database. The vulnerability requires network access and high privileges to exploit, and the exploit has been publicly disclosed. The OS4ED project was notified through an issue report but has not responded at the time of publication.

Critical Impact

Authenticated remote attackers can inject SQL statements through the student save workflow, potentially reading or modifying student information data stored in the openSIS database.

Affected Products

  • OS4ED openSIS-Classic versions up to and including 9.3
  • Component: General Information Tab (modules/students/Student.php)
  • Function: save action processing the students parameter

Discovery Timeline

  • 2026-09-30 - CVE-2026-103113 published to the National Vulnerability Database
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-103113

Vulnerability Analysis

The vulnerability is an improper neutralization of special elements in a data query language construct [CWE-74], commonly referred to as SQL injection. The save action inside modules/students/Student.php handles form submissions from the General Information Tab used to create or update student records. Input passed through the students argument reaches a database query without adequate sanitization or parameterization.

An authenticated user with sufficient application privileges can supply crafted values that break out of the intended query context. Because the injection occurs in a first-party PHP module that touches student records, an attacker can influence read and write operations against the underlying MySQL database used by openSIS. The public disclosure of exploit details increases the likelihood that automated tooling will target vulnerable deployments.

Root Cause

The root cause is the direct concatenation of user-controlled input from the students parameter into an SQL statement inside the save action handler. The code path does not use prepared statements, parameterized queries, or a strict allow-list validation on the input. As a result, any SQL metacharacters supplied by the caller are interpreted by the database engine.

Attack Vector

The attack vector is network-based and requires a valid authenticated session with elevated privileges within openSIS. An attacker submits a manipulated request to the student save endpoint containing a payload in the students argument. The payload alters the intended query and executes attacker-chosen SQL. Because the exploit is publicly available, weaponization is straightforward for anyone with access to a vulnerable openSIS instance. Refer to the GitHub Issue #475 for openSIS and VulDB CVE-2026-103113 Details for the technical writeup.

Detection Methods for CVE-2026-103113

Indicators of Compromise

  • Unusual POST requests to modules/students/Student.php containing SQL metacharacters such as single quotes, UNION, SELECT, --, or ; inside the students parameter.
  • Web server access logs showing repeated save-action requests from a single authenticated session with encoded payloads.
  • MySQL error log entries referencing syntax errors originating from the openSIS application user.
  • Unexpected changes to rows in student-related tables, or new administrative accounts appearing after suspicious save requests.

Detection Strategies

  • Deploy a Web Application Firewall (WAF) with SQL injection rule sets in front of the openSIS instance and enable blocking mode for the /modules/students/ path.
  • Enable MySQL general query logging temporarily to identify queries with injected fragments originating from the openSIS database user.
  • Correlate authenticated user activity in openSIS with database anomalies, focusing on privileged accounts submitting save actions.

Monitoring Recommendations

  • Forward web server, PHP error, and MySQL logs to a centralized logging platform for pattern analysis.
  • Alert on authentication anomalies for administrative openSIS accounts, since exploitation requires high privileges.
  • Baseline normal write volume against student tables and alert on statistically significant deviations.

How to Mitigate CVE-2026-103113

Immediate Actions Required

  • Restrict network access to the openSIS administrative interface to trusted management networks or a VPN.
  • Rotate credentials for privileged openSIS accounts and enforce strong, unique passwords with multi-factor authentication where supported.
  • Review recent database backups and audit logs for signs of tampering against student tables.
  • Monitor the GitHub Repository for openSIS for an upstream fix and subscribe to issue #475 for updates.

Patch Information

No vendor patch is available at the time of publication. According to the CVE description, the OS4ED project was informed of the problem early through an issue report but has not responded. Track the GitHub Issue #475 for openSIS for remediation status.

Workarounds

  • Apply virtual patching via WAF rules that reject SQL metacharacters in the students parameter of modules/students/Student.php.
  • Reduce the number of accounts holding privileges required to invoke the student save action.
  • Place the application behind an authenticating reverse proxy to limit exposure to authenticated internal users only.
  • Consider taking the affected module offline until an official fix is released if the risk to student data outweighs operational needs.
bash
# Example WAF rule (ModSecurity) to block SQL metacharacters in the students parameter
SecRule REQUEST_URI "@contains /modules/students/Student.php" \
    "phase:2,chain,deny,status:403,id:1026103113,\
     msg:'Potential SQLi against openSIS Student.php (CVE-2026-103113)'"
    SecRule ARGS:students "@rx (?i)(union(\s|/\*.*\*/)+select|--|;|/\*|\bor\b\s+\d+=\d+|\bsleep\s*\()" \
        "t:none,t:urlDecodeUni"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.