Reflected XSS Vulnerability in OpenSTAManager by Devcode IT
CVE-2026-24415

5.1MEDIUM

Key Information:

Vendor

Devcode-it

Vendor
CVE Published:
3 March 2026

What is CVE-2026-24415?

OpenSTAManager, a popular open-source management software for technical assistance and invoicing, showcases a Reflected XSS vulnerability in its invoice/order/contract modification modals. The flaw arises from the failure to sanitize user-supplied input from the 'righe' GET parameter before it is reflected in the HTML output. This lack of proper sanitization exposes users to potential exploitation, allowing attackers to inject arbitrary HTML and JavaScript into the application. As a result, users could unknowingly execute malicious scripts, compromising their data and access.

Affected Version(s)

openstamanager <= 2.9.8

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.