Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensips
Opensips opensips |
|
| Vendors & Products |
Opensips
Opensips opensips |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Time‑Based Blind SQL Injection in OpenSIPS Control Panel's Alias Management Module |
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Time‑Based Blind SQL Injection in OpenSIPS Control Panel's Alias Management Module |
Tue, 16 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Mon, 15 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-16T13:40:32.892Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36670
Updated: 2026-06-16T13:40:13.527Z
Status : Deferred
Published: 2026-06-15T20:16:26.020
Modified: 2026-06-16T15:51:54.823
Link: CVE-2026-36670
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:30:16Z