CVE-2026-36670: SQL Injection
A Time-Based Blind SQL Injection vulnerability in the aliasmanagement module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in aliasmanagement.php.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
opensips-cpto a version that resolves this vulnerability.Fixed in 9.3.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36670?
CVE-2026-36670 has a high severity rating of 8.8 according to the CVSS 3.1 standard.
How do I fix CVE-2026-36670?
To fix CVE-2026-36670, update OpenSIPS Control Panel to version 9.3.3 or later.
What type of vulnerability is CVE-2026-36670?
CVE-2026-36670 is a Time-Based Blind SQL Injection vulnerability.
What component is affected by CVE-2026-36670?
CVE-2026-36670 affects the alias_management module of the OpenSIPS Control Panel.
Can CVE-2026-36670 be exploited remotely?
Yes, CVE-2026-36670 can be exploited remotely by authenticated attackers via the 'table' GET parameter.