CVE-2026-36670

HIGH

OpenSIPS Control Panel < 9.3.3 - Authenticated Time-Based Blind SQL Injection via Alias Management Table Parameter

Title source: llm
STIX 2.1

Description

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php.

Scores

CVSS v3 8.8
EPSS 0.0036
EPSS Percentile 27.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Published Jun 15, 2026
Tracked Since Jun 16, 2026