VYPR

OPMS

by Lock Upme

CVEs (2)

  • CVE-2020-20595MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.

  • CVE-2026-19354MedAug 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql…