CVE-2020-6143
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An attacker can send an HTTP request to trigger this vulnerability.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 10.78%
- CWE
- CWE-96
- Published
- 2020-09-01
- Last modified
- 2026-03-14
Affected products
- n/a OS4Ed
Weakness type
Related vulnerabilities
- CVE-2024-55877 — XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2020-6144 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable wh
- CVE-2024-55662 — XWiki allows remote code execution through the extension sheet
- CVE-2015-2079 — Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the t
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allo
- CVE-2022-43938 — Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
- CVE-2024-43400 — XWiki Platform allows XSS through XClass name in string properties