SQL Injection Vulnerability in lock-upme OPMS by Unknown Vendor
CVE-2026-19354

5.3MEDIUM

Key Information:

Vendor

Lock-upme

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19354?

A vulnerability has been identified in the lock-upme OPMS software, specifically in the IN Clause Handler located in the messages controller (message.go). This flaw allows an attacker to manipulate input parameters, leading to SQL injection attacks that can be executed remotely. The affected version has been noted as up to commit 831440f37a92c1568f2e071d5233bc873a9d8b09. The vendor has not provided a timely response regarding this disclosure, which raises concerns about the software's security management. Users of this product should address potential risks immediately.

Affected Version(s)

OPMS 831440f37a92c1568f2e071d5233bc873a9d8b09

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

N1y1 (VulDB User)
VulDB CNA Team
.