Description
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.
INFO
Published Date :
2026-04-28T13:43:24.366Z
Last Modified :
2026-04-28T15:45:23.262Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2026-27760 vulnerability.
| Vendors | Products |
|---|---|
| Opencats |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-27760.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact