Impact
This vulnerability is a classic SQL injection flaw in Ocsreports version prior to 2.12.6. The application fails to sanitize user‑supplied values in the selected_grp_dupli[] parameter of the /ocsreports/index.php?function=admin_double endpoint, allowing an authenticated operator to inject malicious SQL and retrieve database contents. The weakness is classified as CWE‑89 and could expose sensitive inventory data to the attacker.
Affected Systems
The affected product is the OCS Inventory NG Ocsreports module. All releases older than 2.12.6 are vulnerable. Users running the Ocsreports component in any OCS Inventory NG deployment should verify their software version and apply the latest update.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity flaw. Because the EPSS score is not available, the current exploitation probability is unknown, but the lack of a KEV listing does not lower the urgency; the risk remains significant in environments where operator accounts exist. The likely attack requires the attacker to authenticate with operator privileges, which may be achieved through social engineering, credential theft or compromise of an existing operator account. Until patched, the potential to read confidential database information persists.
OpenCVE Enrichment