PT-2026-49288 · Unknown · Opensips Control Panel
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSIPS Control Panel versions prior to 9.3.3
Description
A Time-Based Blind SQL Injection in the alias management module allows authenticated attackers to execute arbitrary SQL commands. This occurs via the 'table' GET parameter in the 'alias management.php' endpoint. Time-Based Blind SQL Injection is a technique where an attacker sends SQL queries and observes the time the server takes to respond to determine if the query was successful.
Recommendations
Update to version 9.3.3 or later.
As a temporary workaround, restrict access to the 'alias management.php' endpoint or avoid using the
table parameter until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensips Control Panel