
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35470 is a SQL Injection vulnerability affecting six confronta_righe.php modal files across different modules in OpenSTAManager versions <= 2.10.1. The flaw allows authenticated attackers with low privileges to inject arbitrary SQL statements via the unsanitized righe GET parameter. It was published to the GitHub Advisory Database on April 3, 2026, and assigned GHSA-mmm5-3g4x-qw39. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In all six affected files, the righe parameter is retrieved directly from $_GET['righe'] and concatenated without sanitization, parameterization, or validation into a raw SQL IN() clause (e.g., WHERE in_righe_interventi.id IN ('.$righe.')). An attacker with an authenticated session and access to any of the affected modules (fatture, interventi, preventivi, ordini, ddt, contratti) can craft a GET request with a malicious righe value using error-based SQL injection techniques such as EXTRACTVALUE() to exfiltrate data. No complex preconditions are required beyond a valid low-privilege session and at least one existing record in the target module (GitHub Advisory, OpenSTAManager Advisory).
Successful exploitation results in high impact across confidentiality, integrity, and availability. An attacker can extract the full database contents — including bcrypt-hashed user credentials from zz_users, customer data, invoices, contracts, and all other stored records. Integrity can be compromised through injected INSERT, UPDATE, or DELETE statements, and availability can be disrupted via table deletion or database corruption. The breadth of affected modules (invoices, orders, interventions, contracts, DDT, quotes) means virtually all business-critical data managed by OpenSTAManager is at risk (GitHub Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, including concrete HTTP GET requests with crafted SQL injection payloads that have been demonstrated to extract credentials (OpenSTAManager Advisory). Feedly classifies the exploit confidence as high and confirms it is a real exploit with demonstrated results. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.014% (3rd percentile), indicating low predicted exploitation probability in the near term. The vulnerability is not listed in the CISA KEV catalog.
id_record=1) and the corresponding id_module value (e.g., id_module=3 for Interventi).righe parameter. For example:GET /modules/interventi/modals/confronta_righe.php?id_module=3&id_record=1&righe=1)%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,(SELECT%20CONCAT(username,0x3a,password)%20FROM%20zz_users%20LIMIT%201)))%23XPATH syntax error: '~admin:$2y$10$qAo04wNbhR9cpxjHzr').confronta_righe.php endpoints (e.g., /modules/interventi/modals/confronta_righe.php, /modules/fatture/modals/confronta_righe.php) with righe parameter values containing SQL keywords such as AND, EXTRACTVALUE, CONCAT, SELECT, UNION, or URL-encoded equivalents (%20AND%20, %23).confronta_righe.php with abnormally long or encoded righe parameter values; MySQL/application error logs containing SQLSTATE[HY000]: General error: 1105 XPATH syntax error messages, which indicate successful error-based SQL injection.righe payloads, suggesting automated enumeration.EXTRACTVALUE, CONCAT, zz_users, or other sensitive tables appearing in MySQL general query logs or slow query logs.Upgrade OpenSTAManager to version 2.10.2 or later, which explicitly patches the SQL Injection vulnerability in all six confronta_righe.php files by applying parameterized queries (OpenSTAManager Release). The fix involves casting the righe input to integer values and using placeholder-based prepared statements instead of direct string concatenation. As a temporary workaround prior to patching, restrict access to the affected modal endpoints at the web server or firewall level, and enforce the principle of least privilege for database accounts used by the application. Additionally, monitor database and web server logs for SQL injection patterns targeting the confronta_righe.php endpoints (GitHub Advisory).
The vulnerability was reported by security researcher Omar Ramirez (GitHub: ormzro) and published via the GitHub Security Advisory program on April 1, 2026. Coverage appeared on The Hacker Wire and was noted on Bluesky and Mastodon by automated CVE tracking accounts. INCIBE-CERT (Spain's national cybersecurity agency) also published an early warning advisory for the vulnerability. No major vendor statements or significant community debate beyond standard disclosure channels have been observed (The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."