PT-2026-22426 · Opendcim · Opendcim
Valentin Lobstein
·
Published
2026-02-27
·
Updated
2026-03-10
·
CVE-2026-28516
CVSS v4.0
9.3
Critical
| AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openDCIM versions through 23.04 commit 4467e9c4
Description
The software contains a SQL injection issue in the
Config::UpdateParameter function. The install.php and container-install.php handlers directly incorporate user-provided input into SQL statements using string interpolation, lacking prepared statements or adequate input sanitization. An authenticated user can execute arbitrary SQL statements against the database. The vulnerable parameters are passed to the SQL statements without proper validation.Recommendations
Versions prior to 23.04 commit 4467e9c4 should be updated.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opendcim