S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-40542 Scanner

CVE-2021-40542 scanner - Cross-Site Scripting (XSS) vulnerability in Opensis-Classic

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-40542
6.1
CVSS

Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

OpenSIS-Classic Version 8.0 is an open-source school management system. It helps administrators to manage academic records, such as attendance, assessment, schedules, and grading, and generate reports, such as transcripts, progress cards, and certificates, of students in K-12 schools and colleges. OpenSIS-Classic is designed to work on Windows, Linux, or Mac OS and supports MySQL, PostgreSQL, and Oracle as a database management system. OpenSIS-Classic provides a web-based user interface where teachers, students, and parents can access and share information securely. 

CVE-2021-40542 is a security vulnerability that affects OpenSIS-Classic Version 8.0. This vulnerability allows an attacker, who does not have to be authenticated or authorized, to inject malicious scripts into the link_url parameter in Ajax_url_encode.php. This parameter is commonly used in the URL of the page to retrieve data from the server or execute a specific function. The scripts injected by the attacker can be executed by the victim's web browser in the context of the vulnerable web application, which can lead to a cross-site scripting (XSS) attack. 

When this vulnerability is exploited, an attacker can steal sensitive data, such as user credentials, session cookies, or personal information, from the victim's browser and send it to the attacker's server or perform malicious actions, such as redirecting the victim to a phishing page, downloading malware, or defacing the website. The impact of this vulnerability depends on the intention and skill level of the attacker and the sensitivity and volume of the targeted data. 

S4E is a pro cybersecurity platform that enables users to scan and monitor their digital assets, such as websites, APIs, and mobile apps, for security vulnerabilities and compliance risks. Thanks to the advanced features of S4E, such as automated scanning, prioritized reporting, and actionable insights, OpenSIS-Classic users can easily and quickly identify and remediate CVE-2021-40542 and other vulnerabilities that threaten their data and reputation. Furthermore, S4E provides personalized support and training to help users enhance their security posture and reduce their exposure to cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, OpenSIS-Classic users can take the following precautions:

  • Update to the latest version of OpenSIS-Classic, which has fixed this vulnerability.
  • Configure a web application firewall (WAF) to block malicious requests that contain suspicious scripts or patterns in the URL or request body.
  • Restrict access to the Ajax_url_encode.php file and its parameters to trusted users and IP addresses only.
  • Train users to avoid clicking on suspicious links or downloading files from unverified sources.
  • Monitor web application logs and network traffic to detect and respond to XSS attacks in real-time.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.