Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27012

Опубликовано: 03 мар. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:*
Версия до 2.9.8 (включая)

EPSS

Процентиль: 9%
0.0003
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
github
24 дня назад

OpenSTAManager affected by unauthenticated privilege escalation via modules/utenti/actions.php

EPSS

Процентиль: 9%
0.0003
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306