A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a manipulation of the argument system.user.query results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Sun, 31 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a manipulation of the argument system.user.query results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | OFCMS ComnController ComnController.java query sql injection | |
| First Time appeared |
Ofcms
Ofcms ofcms |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:ofcms:ofcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ofcms
Ofcms ofcms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-31T16:15:15.527Z
Updated: 2026-05-31T16:15:15.527Z
Reserved: 2026-05-30T17:58:10.154Z
Link: CVE-2026-10193
No data.
Status : Received
Published: 2026-05-31T17:16:31.417
Modified: 2026-05-31T17:16:31.417
Link: CVE-2026-10193
No data.