Time-Based Blind SQL Injection Vulnerability in OpenSTAManager by devcode-it
CVE-2026-28805
8.8HIGH
What is CVE-2026-28805?
OpenSTAManager, an open-source management software, contains a vulnerability that allows authenticated attackers to exploit multiple AJAX select handlers via the options[stato] GET parameter. The flaw arises from the direct concatenation of user-supplied input into SQL WHERE clauses without proper sanitation. This can lead to the execution of arbitrary SQL statements, potentially exposing sensitive information such as usernames, password hashes, and financial records stored in the MySQL database. Version 2.10.2 addresses this issue and it's essential for users to update immediately.
Affected Version(s)
openstamanager < 2.10.2
