PT-2026-84975 · Ocs Inventory · Ocsreports

CVE-2026-76176

·

Publicado

2026-09-03

·

Atualizado

2026-09-03

CVSS v4.0

8.6

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin double due to improper processing of the values in the ID field included in the selected grp dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-76176

Produtos afetados

Ocsreports