| BDSA-2026-3100 |
|
Critical |
Mar 11, 2026 |
openDCIM is vulnerable to remote code execution (RCE) due to improper handling of the `dot` configuration parameter in `report_network_map.php`. This c
more...
openDCIM is vulnerable to remote code execution (RCE) due to improper handling of the `dot` configuration parameter in `report_network_map.php`. This could allow an attacker to execute arbitrary commands in the context of the web server process.
less...
|
|
| BDSA-2026-3099 |
|
Critical |
Mar 11, 2026 |
openDCIM is vulnerable to SQL injection (SQLi) due to improper input handling in the `Config::UpdateParameter` function. This could allow an attacker t
more...
openDCIM is vulnerable to SQL injection (SQLi) due to improper input handling in the `Config::UpdateParameter` function. This could allow an attacker to execute arbitrary SQL statements against the underlying database.
less...
|
|
| BDSA-2026-3098 |
|
Critical |
Mar 11, 2026 |
openDCIM is vulnerable to missing authorization due to improper role checks in `install.php` and `container-install.php`. This could allow an attacker
more...
openDCIM is vulnerable to missing authorization due to improper role checks in `install.php` and `container-install.php`. This could allow an attacker to modify application configuration without proper privileges.
less...
|
|
| BDSA-2025-4636 |
|
High |
May 27, 2025 |
openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.
**Note: CVE details have been utilized in ge
more...
openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by Black Duck CyRC.**
less...
|
|
| BDSA-2025-11681 |
|
High |
Sep 12, 2025 |
openDCIM is vulnerable to cross-site scripting (XSS) due to improper handling of uploaded `.svg` files. This could allow an attacker to execute arbitra
more...
openDCIM is vulnerable to cross-site scripting (XSS) due to improper handling of uploaded `.svg` files. This could allow an attacker to execute arbitrary scripts in the browser of a user viewing a maliciously crafted SVG file, potentially leading to theft of sensitive data or compromise of user accounts.
less...
|
|