CVE-2025-22925
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-22925 is a recently disclosed SQL injection vulnerability affecting OS4ED openSIS versions 7.0 to 9.1. The issue lies in the AttendanceCodes.php file at the /attendance/ directory, where the table parameter is susceptible to malicious SQL injection attacks. For an attacker to exploit this vulnerability, they must have administrative privileges. This weakness could potentially allow unauthorized access to sensitive data or enable attackers to modify or delete critical information. It is highly recommended that affected organizations apply the necessary patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.