Reflected XSS Vulnerability in OpenSTAManager by Devcode IT
CVE-2026-24415
5.1MEDIUM
What is CVE-2026-24415?
OpenSTAManager, a popular open-source management software for technical assistance and invoicing, showcases a Reflected XSS vulnerability in its invoice/order/contract modification modals. The flaw arises from the failure to sanitize user-supplied input from the 'righe' GET parameter before it is reflected in the HTML output. This lack of proper sanitization exposes users to potential exploitation, allowing attackers to inject arbitrary HTML and JavaScript into the application. As a result, users could unknowingly execute malicious scripts, compromising their data and access.
Affected Version(s)
openstamanager <= 2.9.8
