What is CVE-2026-19354?
A SQL injection vulnerability was identified in lock-upme OPMS up to commit 831440f37a92c1568f2e071d5233bc873a9d8b09, specifically in the IN Clause Handler within the `controllers/messages/message.go` file via the `ids` argument. This allows remote attackers to manipulate database queries, and upgrading to the latest version is recommended as a mitigation.
Azərbaycanca: lock-upme OPMS-in 831440f37a92c1568f2e071d5233bc873a9d8b09 versiyasına qədər olan sistemdə, `controllers/messages/message.go` faylındakı IN Clause Handler komponentinin id parametrində SQL injection zəifliyi aşkarlanıb. Bu, uzaqdan hücum edənə verilənlər bazasını manipulyasiya etməyə imkan verir, təhlükəsizlik tədbiri kimi sistemi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which specific component of lock-upme OPMS does CVE-2026-19354 exist?
This SQL injection vulnerability is found in the IN Clause Handler component within the `controllers/messages/message.go` file, via the `ids` argument.
What security measure is recommended to mitigate CVE-2026-19354?
Upgrading to the latest version is recommended as a mitigation for this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.