Time-Based Blind SQL Injection Vulnerability in OpenSTAManager by devcode-it
CVE-2026-28805

8.8HIGH

Key Information:

Vendor

Devcode-it

Vendor
CVE Published:
2 April 2026

What is CVE-2026-28805?

OpenSTAManager, an open-source management software, contains a vulnerability that allows authenticated attackers to exploit multiple AJAX select handlers via the options[stato] GET parameter. The flaw arises from the direct concatenation of user-supplied input into SQL WHERE clauses without proper sanitation. This can lead to the execution of arbitrary SQL statements, potentially exposing sensitive information such as usernames, password hashes, and financial records stored in the MySQL database. Version 2.10.2 addresses this issue and it's essential for users to update immediately.

Affected Version(s)

openstamanager < 2.10.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.