8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php.
AI Analysis
Time-Based Blind SQL Injection vulnerability in the alias_management module
Basic Information
ID
CVE-2026-36670
Source
mitre
Published
Jun 15, 2026 at 00:00
Modified
Jun 16, 2026 at 13:40
Affected Product
Vendor
OpenSIPS
Product
opensips-cp
Version
< 9.3.3
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
OpenSIPS
Product
OpenSIPS Control Panel
Version
< 9.3.3