CVE-2026-35470: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-35470 is a SQL Injection vulnerability affecting six confronta_righe.php modal files across different modules in OpenSTAManager versions <= 2.10.1. The flaw allows authenticated attackers with low privileges to inject arbitrary SQL statements via the unsanitized righe GET parameter. It was published to the GitHub Advisory Database on April 3, 2026, and assigned GHSA-mmm5-3g4x-qw39. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In all six affected files, the righe parameter is retrieved directly from $_GET['righe'] and concatenated without sanitization, parameterization, or validation into a raw SQL IN() clause (e.g., WHERE in_righe_interventi.id IN ('.$righe.')). An attacker with an authenticated session and access to any of the affected modules (fatture, interventi, preventivi, ordini, ddt, contratti) can craft a GET request with a malicious righe value using error-based SQL injection techniques such as EXTRACTVALUE() to exfiltrate data. No complex preconditions are required beyond a valid low-privilege session and at least one existing record in the target module (GitHub Advisory, OpenSTAManager Advisory).

Impact

Successful exploitation results in high impact across confidentiality, integrity, and availability. An attacker can extract the full database contents — including bcrypt-hashed user credentials from zz_users, customer data, invoices, contracts, and all other stored records. Integrity can be compromised through injected INSERT, UPDATE, or DELETE statements, and availability can be disrupted via table deletion or database corruption. The breadth of affected modules (invoices, orders, interventions, contracts, DDT, quotes) means virtually all business-critical data managed by OpenSTAManager is at risk (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, including concrete HTTP GET requests with crafted SQL injection payloads that have been demonstrated to extract credentials (OpenSTAManager Advisory). Feedly classifies the exploit confidence as high and confirms it is a real exploit with demonstrated results. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.014% (3rd percentile), indicating low predicted exploitation probability in the near term. The vulnerability is not listed in the CISA KEV catalog.

Exploitation steps

  1. Authenticate: Obtain a valid session on the target OpenSTAManager instance (any low-privilege user account with access to at least one affected module such as Interventi, Fatture, Ordini, etc.).
  2. Identify a valid record ID: Browse the target module to identify an existing record ID (e.g., id_record=1) and the corresponding id_module value (e.g., id_module=3 for Interventi).
  3. Craft the injection payload: Construct a GET request targeting one of the six vulnerable endpoints, injecting an error-based SQL payload into the righe parameter. For example:
    GET /modules/interventi/modals/confronta_righe.php?id_module=3&id_record=1&righe=1)%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,(SELECT%20CONCAT(username,0x3a,password)%20FROM%20zz_users%20LIMIT%201)))%23
  4. Extract data from error response: The MySQL error response will contain the exfiltrated data embedded in an XPATH syntax error message (e.g., XPATH syntax error: '~admin:$2y$10$qAo04wNbhR9cpxjHzr').
  5. Enumerate further: Repeat with different subqueries to extract additional tables, user records, customer data, invoice details, or other sensitive information from the database.
  6. Escalate if possible: Use extracted bcrypt password hashes for offline cracking attempts to gain higher-privilege access to the application or reuse credentials against other systems (GitHub Advisory, OpenSTAManager Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to any of the six confronta_righe.php endpoints (e.g., /modules/interventi/modals/confronta_righe.php, /modules/fatture/modals/confronta_righe.php) with righe parameter values containing SQL keywords such as AND, EXTRACTVALUE, CONCAT, SELECT, UNION, or URL-encoded equivalents (%20AND%20, %23).
  • Logs: Web server access logs showing requests to confronta_righe.php with abnormally long or encoded righe parameter values; MySQL/application error logs containing SQLSTATE[HY000]: General error: 1105 XPATH syntax error messages, which indicate successful error-based SQL injection.
  • Application Logs: Repeated requests to modal endpoints from the same authenticated session with varying righe payloads, suggesting automated enumeration.
  • Database: Unexpected queries involving EXTRACTVALUE, CONCAT, zz_users, or other sensitive tables appearing in MySQL general query logs or slow query logs.

Mitigation and workarounds

Upgrade OpenSTAManager to version 2.10.2 or later, which explicitly patches the SQL Injection vulnerability in all six confronta_righe.php files by applying parameterized queries (OpenSTAManager Release). The fix involves casting the righe input to integer values and using placeholder-based prepared statements instead of direct string concatenation. As a temporary workaround prior to patching, restrict access to the affected modal endpoints at the web server or firewall level, and enforce the principle of least privilege for database accounts used by the application. Additionally, monitor database and web server logs for SQL injection patterns targeting the confronta_righe.php endpoints (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher Omar Ramirez (GitHub: ormzro) and published via the GitHub Security Advisory program on April 1, 2026. Coverage appeared on The Hacker Wire and was noted on Bluesky and Mastodon by automated CVE tracking accounts. INCIBE-CERT (Spain's national cybersecurity agency) also published an early warning advisory for the vulnerability. No major vendor statements or significant community debate beyond standard disclosure channels have been observed (The Hacker Wire).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management