PT-2026-45192 · Opencats · Opencats

Published

2026-05-31

·

Updated

2026-05-31

·

CVE-2026-49490

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manipulating filter requests to execute arbitrary SQL queries against the database.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-49490

Affected Products

Opencats