Vulnerability Description
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-36670?
CVE-2026-36670 is a vulnerability with a CVSS score of 8.8 (HIGH). A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL com...
How severe is CVE-2026-36670?
CVE-2026-36670 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-36670?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.