OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based blind injection attacks and read sensitive data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 31 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based blind injection attacks and read sensitive data. | |
| Title | OpenCATS - SQL Injection in DataGrid sortDirection Parameter | |
| First Time appeared |
Opencats
Opencats opencats |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:opencats:opencats:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opencats
Opencats opencats |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-31T12:04:48.034Z
Reserved: 2026-05-31T11:54:34.993Z
Link: CVE-2026-49489
No data.
Status : Received
Published: 2026-05-31T13:16:49.090
Modified: 2026-05-31T13:16:49.090
Link: CVE-2026-49489
No data.
OpenCVE Enrichment
Updated: 2026-05-31T13:30:03Z
Weaknesses