PT-2026-22426 · Opendcim · Opendcim

Valentin Lobstein

·

Published

2026-02-27

·

Updated

2026-03-10

·

CVE-2026-28516

CVSS v4.0

9.3

Critical

AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openDCIM versions through 23.04 commit 4467e9c4
Description The software contains a SQL injection issue in the Config::UpdateParameter function. The install.php and container-install.php handlers directly incorporate user-provided input into SQL statements using string interpolation, lacking prepared statements or adequate input sanitization. An authenticated user can execute arbitrary SQL statements against the database. The vulnerable parameters are passed to the SQL statements without proper validation.
Recommendations Versions prior to 23.04 commit 4467e9c4 should be updated.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-28516

Affected Products

Opendcim