S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41691 Scanner

CVE-2021-41691 scanner - SQL Injection (SQLi) vulnerability in openSIS Student Information System

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-41691
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

OpenSIS Student Information System is a web-based application designed and maintained by Open Solutions for Education, Inc. It caters to K-12 institutions and higher education institutions by providing an open-source platform to manage student information. This system offers a range of features that include attendance tracking, online grade books, student schedules, and a comprehensive reporting system, among others. It is a valuable tool for educational institutions seeking to manage their students' data in an efficient manner.

One of the security risks associated with OpenSIS Student Information System is CVE-2021-41691. This vulnerability exists due to an SQL injection flaw found in the "student_id" and "TRANSFER[SCHOOL]" parameters sent to the TransferredOutModal.php page. This security vulnerability could be exploited by attackers to gain access to private data stored in the database system. When attackers inject malicious code into the parameters in question, they can bypass authentication mechanisms and extract sensitive information that the system is storing.

The exploitation of CVE-2021-41691 vulnerability can result in the exposure of sensitive data. Attackers can access student grades, social security numbers, and other private data. Education institutions can suffer reputational damage and legal consequences as a result of such breaches. It is, therefore, essential to take appropriate measures to protect against this vulnerability.

At S4E, we provide pro features for our security platform that enable users to easily and quickly detect vulnerabilities in their digital assets. With our platform, users can identify vulnerabilities in their systems and implement appropriate measures to protect against them. We encourage organizations to take full advantage of the features we provide to secure their systems and safeguard their data.

 

REFERENCES

Solution Advice

To mitigate this vulnerability, it is recommended that the following precautions be taken:

  • Regularly audit the system for SQL injection vulnerabilities
  • Apply security patches that are provided by the vendor
  • Utilize a web application firewall that can detect and block SQL injection attacks
  • Use parameterized queries to ensure that user input is sanitized
  • Limit the privileges granted to the database user

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-41691 scanner - SQL Injection (SQLi) vulnerability in openSIS Student Information System | S4E