cbcvebase.

Ocs Inventory Ng Ocsreports vulnerabilities

5 known vulnerabilities affecting ocs_inventory_ng/ocsreports.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3

Vulnerabilities

Page 1 of 1
CVE-2026-76174P2CRITICALCVSS 9.4v2.12.62026-09-03
CVE-2026-76174 [CRITICAL] CWE-434 CVE-2026-76174: Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_ Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file types. This allows a user with administrator privileges to upload PHP
nvd
CVE-2026-76175P3HIGHCVSS 8.6v2.12.62026-09-03
CVE-2026-76175 [HIGH] CWE-89 CVE-2026-76175: SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be extracted from the database using SQL in
nvd
CVE-2026-76176P3HIGHCVSS 8.6v2.12.62026-09-03
CVE-2026-76176 [HIGH] CWE-89 CVE-2026-76176: SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to impro SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored i
nvd
CVE-2026-76177P3HIGHCVSS 7.1v2.12.62026-09-03
CVE-2026-76177 [HIGH] CWE-918 CVE-2026-76177: Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external system
nvd
CVE-2026-76178P3CRITICALCVSS 9.2v2.12.62026-09-03
CVE-2026-76178 [CRITICAL] CWE-79 CVE-2026-76178: A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper sanitisation when other administrators access the template customisation view,
nvd
Ocs Inventory Ng Ocsreports vulnerabilities | cvebase