OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
id: CVE-2021-40651
info:
name: OS4Ed OpenSIS Community 8.0 - Local File Inclusion
author: ctfle
...