CVE-2025-22928
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 3, 2025
Updated: Apr 21, 2025
CWE ID 89
Summary
CVE-2025-22928 is a newly discovered SQL injection vulnerability affecting OS4ED openSIS versions 7.0 to 9.1. Hackers can exploit this issue by manipulating the cp_id parameter in the Inbox.php file located within the /modules/messages/ directory. Successful exploitation could allow an attacker to gain unauthorized access to sensitive data, modify or delete records, or even take control of the affected system. Users are strongly urged to apply the available security patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.