search
OS4ED
Trends
- 1Critical vulnerability disclosed in openSIS Classic softwareโผ๐จ EUVD-2026-92806 ๐ Score: 9.3/10 (CVSS v3.1) ๐ฆ Product: openSIS-Classic ๐ข Vendor: OS4ED ๐ Updated: 2026-10-05 ๐ openSIS
A high-severity vulnerability, tracked as EUVD-2026-92806 with a CVSS score of 9.3, has been disclosed in openSIS Classic 9.3, the open-source student information system from vendor OS4ED. The flaw allows an authenticated user with the built-in teacher role to select an arbitrary staff record via the staff_id parameter and trigger harmful actions within the School module. Schools running the platform are being urged to review the advisory and apply fixes.