Impact
An SQL injection flaw exists in the del_check parameter of the \/ocsreports\/\?function=save_query_list endpoint in Ocsreports. When an authenticated user with operator privileges supplies input for del_check, the payload is concatenated directly into an SQL query without parameterisation or validation. This allows the attacker to manipulate the SQL command and retrieve sensitive data from the database, potentially exposing configuration, user information, or other confidential data. The weakness is a classic unauthorized data extraction vulnerability (CWE‑89).
Affected Systems
The affected product is OCS Inventory NG’s Ocsreports component. All releases prior to version 2.12.6 are susceptible, while 2.12.6 and later have applied the fix. The vulnerable CPE string points to the patched product, indicating that earlier releases of the same product contain the flaw. Administrators should verify whether their deployment runs any version below 2.12.6.
Risk and Exploitability
According to the CVSS base score of 8.6, this vulnerability is considered high severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog; however, its high CVSS still indicates a significant risk. Exploitation requires an authenticated operator-level account traveling through the web interface, meaning that an attacker who gains legitimate web access or credentials can leverage this flaw. The lack of a publicly known exploit and absence from KEV does not reduce the need for remediation, given the potential for sensitive data disclosure.
OpenCVE Enrichment