Devcode-It Openstamanager vulnerabilities
17 known vulnerabilities affecting devcode-it/openstamanager.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2025-69212P2HIGHCVSS 8.8≤ 2.9.82026-02-06
CVE-2025-69212 [HIGH] CWE-78 CVE-2025-69212: OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands
ghsanvdosv
CVE-2026-27012P2CRITICALCVSS 9.8≤ 2.9.82026-03-03
CVE-2026-27012 [CRITICAL] CWE-306 CVE-2026-27012: OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account
ghsanvdosv
CVE-2026-35168P2HIGHCVSS 8.8fixed in 2.10.22026-04-02
CVE-2026-35168 [HIGH] CWE-89 CVE-2026-35168: OpenSTAManager is an open source management software for technical assistance and invoicing. Prior t
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature (op=risolvi-conflitti-database) that accepts a JSON array of SQL statements via POST and executes them directly against the database wi
ghsanvdosv
CVE-2025-65103P2HIGHCVSS 8.8fixed in 2.9.52025-11-19
CVE-2025-65103 [HIGH] CWE-89 CVE-2025-65103: OpenSTAManager is an open source management software for technical assistance and invoicing. Prior t
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerability in the API allows any user, regardless of permission level, to execute arbitrary SQL queries. By manipulating the display parameter in an API request, an attacker can exfiltrate, modify, or de
ghsanvdosv
CVE-2025-69215P3HIGHCVSS 8.8≤ 2.9.82026-02-04
CVE-2025-69215 [HIGH] CWE-89 CVE-2025-69215: OpenSTAManager is an open source management software for technical assistance and invoicing. In vers
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability in the Stampe Module. At time of publication, no known patch exists.
ghsanvdosv
CVE-2026-28805P3HIGHCVSS 8.8fixed in 2.10.22026-04-02
CVE-2026-28805 [HIGH] CWE-89 CVE-2026-28805: OpenSTAManager is an open source management software for technical assistance and invoicing. Prior t
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection through the options[stato] GET parameter. The user-supplied value is read from $superselect['stato'] and concatenated directly into SQL WHE
ghsanvdosv
CVE-2025-69213P3HIGHCVSS 8.8≤ 2.9.82026-02-04
CVE-2025-69213 [HIGH] CWE-89 CVE-2025-69213: OpenSTAManager is an open source management software for technical assistance and invoicing. In vers
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists in the ajax_complete.php endpoint when handling the get_sedi operation. An authenticated attacker can inject malicious SQL code through the idanagrafica parameter, leading to unauthorized database
ghsanvdosv
CVE-2026-35470P3HIGHCVSS 8.8fixed in 2.10.22026-04-06
CVE-2026-35470 [HIGH] CWE-89 CVE-2026-35470: OpenSTAManager is an open source management software for technical assistance and invoicing. Prior t
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager contain an SQL Injection vulnerability. The righe parameter received via $_GET['righe'] is directly concatenated into an SQL query without any sanitization, parameterization o
ghsanvdosv
CVE-2025-69214P3HIGHCVSS 8.8≤ 2.9.82026-02-06
CVE-2025-69214 [HIGH] CWE-89 CVE-2025-69214: OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling the componenti operation. An authenticated attacker can inject malicious SQL code through the options[matricola] parameter.
ghsanvdosv
CVE-2026-29782P3HIGHCVSS 7.2fixed in 2.10.22026-04-02
CVE-2026-29782 [HIGH] CWE-502 CVE-2026-29782: OpenSTAManager is an open source management software for technical assistance and invoicing. Prior t
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permissions = true). It loads a record from the zz_oauth2 table using the attacker-controlled GET parameter state, and during the OAuth2 configuration flow cal
ghsanvdosv
CVE-2026-38751P3HIGH≥ 0, ≤ 2.10-beta2026-05-04
CVE-2026-38751 [HIGH] CWE-434 OpenSTAManager contains an arbitrary file upload vulnerability in its module update functionality
OpenSTAManager contains an arbitrary file upload vulnerability in its module update functionality
OpenSTAManager versions 2.10 and earlier contain an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php).
ghsa
CVE-2026-24416P3MEDIUMCVSS 6.5≤ 2.9.82026-02-06
CVE-2026-24416 [MEDIUM] CWE-89 CVE-2026-24416: OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTA
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the article pricing completion handler. The application fails to properly sanitize the idarticolo parameter before using it in SQL queries, allowing attackers
ghsanvdosv
CVE-2026-24417P3MEDIUMCVSS 6.5≤ 2.9.82026-02-06
CVE-2026-24417 [MEDIUM] CWE-89 CVE-2026-24417: OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTA
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the global search functionality. The application fails to properly sanitize the term parameter before using it in SQL LIKE clauses across multiple module-spec
nvd
CVE-2026-24418P3MEDIUMCVSS 6.5≤ 2.9.82026-02-06
CVE-2026-24418 [MEDIUM] CWE-89 CVE-2026-24418: OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTA
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module. The application fails to validate that elements of the id_records array are integers bef
ghsanvdosv
CVE-2025-69216P3MEDIUMCVSS 6.5≤ 2.9.82026-02-06
CVE-2025-69216 [MEDIUM] CWE-89 CVE-2025-69216: OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an authenticated SQL injection vulnerability in OpenSTAManager's Scadenzario (Payment Schedule) print template allows any authenticated user to extract sensitive data from the database, including admin credentials, customer information,
ghsanvdosv
CVE-2026-24419P3MEDIUMCVSS 6.5≤ 2.9.82026-02-06
CVE-2026-24419 [MEDIUM] CWE-89 CVE-2026-24419: OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTA
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the Prima Nota (Journal Entry) module's add.php file. The application fails to validate that comma-separated values from the id_documenti GET parameter are integer
ghsanvdosv
CVE-2026-24415P4MEDIUMCVSS 6.1≤ 2.9.82026-03-03
CVE-2026-24415 [MEDIUM] CWE-79 CVE-2026-24415: OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTA
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contains Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the righe GET parameter before reflecting it in HTML output.The $_GET['
ghsanvdosv