CVE-2026-103116 openSIS-Classic SQL注入漏洞
影响攻击者可远程注入SQL语句,读取或篡改数据库数据
OS4ED openSIS-Classic 9.3 及之前版本的 functions/GetStuListFnc.php 文件中,DBQuery 函数对学生列表搜索端点的 LO_sort 参数处理不当,存在 SQL 注入漏洞。该漏洞可被远程利用,且利用代码已公开。厂商已通过 issue 报告获知该问题,但尚未作出回应。
影响范围
OS4ED openSIS-Classic 9.3 及更早版本(依据公开描述,具体受影响版本范围以官方公告为准,暂无更多公开信息)。
漏洞详情
漏洞类型为 SQL 注入。成因是学生列表搜索接口未对 LO_sort 参数进行充分的过滤或参数化处理,直接将其拼接到 SQL 查询中。攻击者可通过构造恶意排序参数,远程向数据库注入任意 SQL 语句,从而读取、修改或删除数据。
利用条件与风险
利用前提是目标系统开放学生列表搜索接口且可被远程访问,无需认证信息(依据公开描述)。由于利用代码已公开,实战中被扫描和攻击的风险较高。
修复建议
官方尚未发布修复版本或回应,建议关注 OS4ED 官方更新。临时缓解措施包括:对 LO_sort 等参数实施严格白名单校验、使用参数化查询,或通过 WAF/访问控制限制该接口的访问。
A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.