PT-2026-45191 · Opencats · Opencats

·

CVE-2026-49489

·

Published

2026-05-31

·

Updated

2026-05-31

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenCATS versions prior to 0.9.7.5
Description An issue exists in the DataGrid component where authenticated users can extract database contents. Attackers can perform time-based blind SQL injection—a technique used to infer data by observing the time the server takes to respond to specific queries—by injecting malicious SQL via the sortDirection parameter in the 'ajax/getDataGridPager.php' endpoint.
Recommendations Update to a version newer than 0.9.7.4. As a temporary workaround, restrict or avoid using the sortDirection parameter in the 'ajax/getDataGridPager.php' endpoint.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49489
GHSA-8MC8-5GW6-C7W4

Affected Products

Opencats