SQL Injection Vulnerability in lock-upme OPMS by Unknown Vendor
CVE-2026-19354
5.3MEDIUM
What is CVE-2026-19354?
A vulnerability has been identified in the lock-upme OPMS software, specifically in the IN Clause Handler located in the messages controller (message.go). This flaw allows an attacker to manipulate input parameters, leading to SQL injection attacks that can be executed remotely. The affected version has been noted as up to commit 831440f37a92c1568f2e071d5233bc873a9d8b09. The vendor has not provided a timely response regarding this disclosure, which raises concerns about the software's security management. Users of this product should address potential risks immediately.
Affected Version(s)
OPMS 831440f37a92c1568f2e071d5233bc873a9d8b09
