CVE-2026-24418

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module. The application fails to validate that elements of the id_records array are integers before using them in an SQL IN() clause, allowing attackers to inject arbitrary SQL commands and extract sensitive data through XPATH error messages.
Configurations

Configuration 1 (hide)

cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:23

Type Values Removed Values Added
Summary
  • (es) OpenSTAManager es un software de gestión de código abierto para asistencia técnica y facturación. OpenSTAManager v2.9.8 y versiones anteriores contienen una crítica vulnerabilidad de inyección SQL basada en errores en el manejador de operaciones masivas para el módulo Scadenzario (Calendario de Pagos). La aplicación no valida que los elementos del array id_records sean enteros antes de usarlos en una cláusula SQL IN(), permitiendo a los atacantes inyectar comandos SQL arbitrarios y extraer datos sensibles a través de mensajes de error XPATH.

09 Feb 2026, 21:42

Type Values Removed Values Added
References () https://github.com/devcode-it/openstamanager/security/advisories/GHSA-4xwv-49c8-fvhq - () https://github.com/devcode-it/openstamanager/security/advisories/GHSA-4xwv-49c8-fvhq - Exploit, Vendor Advisory
CPE cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Devcode openstamanager
Devcode

06 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 19:16

Updated : 2026-06-17 10:23


NVD link : CVE-2026-24418

Mitre link : CVE-2026-24418

CVE.ORG link : CVE-2026-24418


JSON object : View

Products Affected

devcode

  • openstamanager
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')