OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection through the options[stato] GET parameter. The user-supplied value is read from $superselect['stato'] and concatenated directly into SQL WHERE clauses as a bare expression, without any sanitization, parameterization, or allowlist validation. An authenticated attacker can inject arbitrary SQL statements to extract sensitive data from the database, including usernames, password hashes, financial records, and any other information stored in the MySQL database. This issue has been patched in version 2.10.2.
References
| Link | Resource |
|---|---|
| https://github.com/devcode-it/openstamanager/commit/50b9089c506ba2ca249afb1dfead2af5d42c10e7 | Patch |
| https://github.com/devcode-it/openstamanager/commit/679c40fa5b3acad4263b537f367c0695ff9666dc | Patch |
| https://github.com/devcode-it/openstamanager/releases/tag/v2.10.2 | Product Release Notes |
| https://github.com/devcode-it/openstamanager/security/advisories/GHSA-3gw8-3mg3-jmpc | Exploit Mitigation Vendor Advisory |
Configurations
History
07 Apr 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/devcode-it/openstamanager/commit/50b9089c506ba2ca249afb1dfead2af5d42c10e7 - Patch | |
| References | () https://github.com/devcode-it/openstamanager/commit/679c40fa5b3acad4263b537f367c0695ff9666dc - Patch | |
| References | () https://github.com/devcode-it/openstamanager/releases/tag/v2.10.2 - Product, Release Notes | |
| References | () https://github.com/devcode-it/openstamanager/security/advisories/GHSA-3gw8-3mg3-jmpc - Exploit, Mitigation, Vendor Advisory | |
| CPE | cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:* | |
| First Time |
Devcode openstamanager
Devcode |
02 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 14:16
Updated : 2026-04-07 21:17
NVD link : CVE-2026-28805
Mitre link : CVE-2026-28805
CVE.ORG link : CVE-2026-28805
JSON object : View
Products Affected
devcode
- openstamanager
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
