CVE 8.7 HIGH

OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module_CVE-2026-24416

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the article pricing completion handler. The application fails to properly sanitize the idarticolo parameter before using it in SQL queries, allowing attackers to inject arbitrary SQL commands and extract sensitive data through time-based Boolean inference.

AI Analysis

Time-Based Blind SQL Injection vulnerability in the article pricing completion handler

Basic Information

ID CVE-2026-24416
Source GitHub_M
Published Feb 6, 2026 at 18:08

Affected Product

Vendor devcode-it
Product openstamanager
Version <= 2.9.8
Affected Versions devcode-it openstamanager <= 2.9.8

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor devcode-it
Product OpenSTAManager
Version 2.9.8 and earlier

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.