VYPR
Unrated severityNVD Advisory· Published Feb 27, 2026· Updated Mar 2, 2026

openDCIM <= 23.04 SQL Injection in Config::UpdateParameter

CVE-2026-28516

Description

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

1