Key Information Vulnerability Description Vulnerability Type: SQL Injection Affected Software: OpenCATS Version: v0.9.6 Function: 'Tag Deletion' Parameter: Vulnerability Details An attacker can inject SQL code into the parameter, which is used in a DELETE statement, allowing for SQL injection. Solution Upgrade: Upgrade to OpenCATS v0.9.7 or later. Proof of Concept (PoC) Potential Impact Attackers can exploit time-based blind SQL injection to extract data from the entire database.