CVE-2025-65236: SQL Injection
Published Nov 26, 2025
·Updated
OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.
Affected Software
2 affected components
OpenCode Systems USSD Gateway OC
OpenCode USSD Gateway=6.13.11
Event History
Nov 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65236?
CVE-2025-65236 has been classified as a high severity vulnerability due to its potential for unauthorized data access.
2
How do I fix CVE-2025-65236?
To fix CVE-2025-65236, you should sanitize the input for the Session ID parameter and implement parameterized queries to prevent SQL injection.
3
Which software is affected by CVE-2025-65236?
CVE-2025-65236 affects OpenCode Systems USSD Gateway OC Release: 5.
4
What type of vulnerability is CVE-2025-65236?
CVE-2025-65236 is a SQL injection vulnerability that can be exploited through the Session ID parameter.
5
What endpoint is associated with CVE-2025-65236?
CVE-2025-65236 is associated with the /occontrolpanel/index.php endpoint in the affected software.