CVE-2026-28517
- EPSS 0.2%
- Veröffentlicht 27.02.2026 22:12:08
- Zuletzt bearbeitet 10.03.2026 14:40:33
openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it directly to exec() without validati...
CVE-2026-28516
- EPSS 0.02%
- Veröffentlicht 27.02.2026 22:11:52
- Zuletzt bearbeitet 10.03.2026 14:46:09
openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation wi...
CVE-2026-28515
- EPSS 0.11%
- Veröffentlicht 27.02.2026 22:11:37
- Zuletzt bearbeitet 10.03.2026 15:03:39
openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role che...