CVE-2026-35168
PHP vulnerability analysis and mitigation

Overview

CVE-2026-35168 is an authenticated SQL injection vulnerability in the Aggiornamenti (Updates) module of OpenSTAManager, an open source management software for technical assistance and invoicing. The vulnerability affects all versions up to and including 2.10.1, and was disclosed on April 1–2, 2026, with a patch released in version 2.10.2. It carries a CVSS v3.1 base score of 8.8 (High), reflecting network-based exploitation requiring only low-privilege authentication (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-89 (SQL Injection): the op=risolvi-conflitti-database action in modules/aggiornamenti/actions.php (lines 40–82) reads a JSON array of SQL statements from the POST parameter queries, JSON-decodes it, and passes each element directly to $dbo->query() without any validation, allowlist, or sanitization. Before executing the user-supplied queries, the application explicitly disables foreign key checks via SET FOREIGN_KEY_CHECKS=0, further undermining database integrity protections. Additionally, exception messages containing database structure details are returned in the JSON response, leaking internal schema information. The only access control is module-level rw permission on the Aggiornamenti module, which is granted to the default admin account and can be assigned to other user groups (GitHub Advisory).

Impact

An authenticated attacker with rw access to the Aggiornamenti module can execute arbitrary SQL commands — including CREATE, DROP, ALTER, INSERT, UPDATE, DELETE, and SELECT INTO OUTFILE — against the underlying MySQL database. This enables complete database exfiltration (credentials, PII, financial data, configuration secrets), full data manipulation (creating rogue admin accounts, modifying financial records, planting backdoors), and availability disruption via dropping critical tables or resource-intensive queries. Depending on MySQL server configuration, SELECT ... INTO OUTFILE or MySQL User Defined Functions (UDFs) could be leveraged to write arbitrary files or execute OS commands, potentially escalating to full remote code execution (GitHub Advisory).

Exploitability

A working proof-of-concept Python exploit (poc_sql.py) is publicly available in the GitHub Security Advisory, providing step-by-step instructions including authentication, module ID detection, and crafted HTTP POST requests with JSON-encoded SQL payloads. The EPSS score is approximately 0.061% (0.000610), indicating currently low predicted exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and reported by researcher Omar Ramirez (ormzro) (GitHub Advisory, Feedly).

Exploitation steps

  1. Authenticate: Send a POST request to /index.php with op=login&username=<user>&password=<pass>. Save the returned PHPSESSID cookie upon successful redirect to controller.php.
  2. Identify the Aggiornamenti module ID: Navigate to the application dashboard and inspect sidebar links for id_module= values associated with the "Aggiornamenti" module. The default value in a standard installation is 6; alternatively, probe common IDs (4–8) by checking page content.
  3. Craft the malicious POST request: Send a POST to /editor.php?id_module=6&id_record=6 with Content-Type: application/x-www-form-urlencoded and the body: op=risolvi-conflitti-database&queries=<URL-encoded JSON array of SQL statements>.
  4. Inject arbitrary SQL: The URL-decoded queries parameter contains a JSON array such as ["DROP TABLE IF EXISTS poc_test", "CREATE TABLE poc_test (id INT AUTO_INCREMENT PRIMARY KEY, proof VARCHAR(255))", "INSERT INTO poc_test (proof) VALUES ('pwned')"]. Any valid MySQL statement is accepted.
  5. Confirm execution: The server responds with HTTP 200 and a JSON body containing {"success":true,"message":"Tutte le query sono state eseguite con successo (3 query)..."}, confirming all statements were executed.
  6. Escalate (optional): Use SELECT ... INTO OUTFILE to write a web shell to the server filesystem, or extract sensitive data (e.g., SELECT * FROM zz_users) via INSERT-based exfiltration techniques, depending on MySQL FILE privilege and secure_file_priv configuration (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP POST requests to /editor.php?id_module=<N>&id_record=<N> with op=risolvi-conflitti-database in the body; URL-encoded JSON arrays in the queries parameter containing SQL keywords (DROP, CREATE, INSERT, SELECT, OUTFILE).
  • Logs: Web server access logs showing repeated POST requests to /editor.php with op=risolvi-conflitti-database; application logs recording execution of unexpected SQL statements (e.g., DDL operations outside normal update cycles).
  • Database: Presence of unexpected tables (e.g., poc_vuln04_verify, poc_vuln04_marker) or newly created admin accounts in zz_users; modified financial records or configuration entries; files written to the web root via SELECT INTO OUTFILE.
  • File System: Unexpected PHP or script files in the OpenSTAManager web directory, potentially written via MySQL SELECT INTO OUTFILE if FILE privilege is enabled.
  • Process: MySQL process list showing unusual DDL or DML queries originating from the OpenSTAManager database user outside of normal application update windows (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade OpenSTAManager to version 2.10.2 or later, which implements a SQL allowlist in modules/aggiornamenti/actions.php restricting accepted queries to safe patterns (e.g., ALTER TABLE, CREATE INDEX, DROP INDEX, UPDATE zz_views, INSERT INTO zz_*, DELETE FROM zz_*) and removes the SET FOREIGN_KEY_CHECKS=0 call (GitHub Release, Patch Commit). As interim workarounds: restrict access to the Aggiornamenti module to trusted administrators only; implement network-level controls (firewall, VPN) to limit who can reach the OpenSTAManager application; and monitor database logs for suspicious DDL/DML activity. Error messages from the endpoint should also be sanitized to prevent database schema leakage (GitHub Advisory).

Community reactions

The vulnerability received coverage from threat intelligence outlets including The Hacker Wire and Yazoul.net shortly after disclosure. Social media activity was observed on Bluesky and Mastodon, primarily from automated CVE tracking accounts. No significant vendor statements beyond the GitHub Security Advisory and patch release have been identified, and community reaction has been moderate given the niche scope of the affected software (The Hacker Wire, Yazoul Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-8cfw-pcwh-v63wHIGH8.4
  • PHP logoPHP
  • winter/wn-system-module
NoYesAug 20, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-fm29-4mq3-phg6MEDIUM5.3
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-mpmw-f6h6-3g26MEDIUM4.3
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management