openSIS Student Information System version 8.0 is susceptible to SQL injection via the student_id and TRANSFER[SCHOOL] parameters in POST request sent to /TransferredOutModal.php.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view