Логотип exploitDog
bind:CVE-2026-24418
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-24418

Количество 2

Количество 2

nvd логотип

CVE-2026-24418

2 дня назад

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module. The application fails to validate that elements of the id_records array are integers before using them in an SQL IN() clause, allowing attackers to inject arbitrary SQL commands and extract sensitive data through XPATH error messages.

EPSS: Низкий
github логотип

GHSA-4xwv-49c8-fvhq

2 дня назад

OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-24418

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module. The application fails to validate that elements of the id_records array are integers before using them in an SQL IN() clause, allowing attackers to inject arbitrary SQL commands and extract sensitive data through XPATH error messages.

0%
Низкий
2 дня назад
github логотип
GHSA-4xwv-49c8-fvhq

OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module

0%
Низкий
2 дня назад

Уязвимостей на страницу