PT-2026-29744 · Unknown · Openstamanager

Ormzro

·

Published

2026-04-02

·

Updated

2026-04-05

·

CVE-2026-35168

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSTAManager versions prior to 2.10.2
Description The OpenSTAManager software contains a flaw in the Aggiornamenti (Updates) module. This module includes a database conflict resolution feature that accepts a JSON array of SQL statements via POST requests to the op=risolvi-conflitti-database endpoint and executes them directly against the database without validation or sanitization. An authenticated attacker with access to the Aggiornamenti module can execute arbitrary SQL statements, including commands like CREATE, DROP, ALTER, INSERT, UPDATE, DELETE, and SELECT INTO OUTFILE. Foreign key checks are disabled before execution, reducing database integrity protections.
Recommendations Update OpenSTAManager to version 2.10.2 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35168
GHSA-2FR7-CC4F-WH98

Affected Products

Openstamanager