Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prmh-rp39-qc4m

Опубликовано: 28 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 8.8

Описание

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.

EPSS

Процентиль: 96%
0.23836
Средний

9.3 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
2 месяца назад

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.

EPSS

Процентиль: 96%
0.23836
Средний

9.3 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89