PT-2026-45191 · Opencats · Opencats

Texuguinho1234

·

Published

2026-05-31

·

Updated

2026-05-31

·

CVE-2026-49489

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based blind injection attacks and read sensitive data.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-49489

Affected Products

Opencats