在端点 /ocsreports/index.php?function=admin_double 中存在 SQL 注入漏洞,原因是对 selected_grp_dupli[] 参数中包含的 ID 字段值处理不当。具有操作员权限的已认证用户可以操纵这些值,从而改变应用程序执行的 SQL 查询,进而获取存储在数据库中的信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OCS Inventory NG | Ocsreports | 2.12.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OCS Inventory NG | Ocsreports | 2.12.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76174 | 9.4 CRITICAL | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76178 | 9.2 CRITICAL | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76175 | 8.6 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76177 | 7.1 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
No comments yet