CVE-2025-22925

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 89

Summary

CVE-2025-22925 is a recently disclosed SQL injection vulnerability affecting OS4ED openSIS versions 7.0 to 9.1. The issue lies in the AttendanceCodes.php file at the /attendance/ directory, where the table parameter is susceptible to malicious SQL injection attacks. For an attacker to exploit this vulnerability, they must have administrative privileges. This weakness could potentially allow unauthorized access to sensitive data or enable attackers to modify or delete critical information. It is highly recommended that affected organizations apply the necessary patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share