Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/devcode-it/openstamanager

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-38751: n/aCVE-2026-38751
0

OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in its module update functionality. This vulnerability allows an attacker with high privileges to upload arbitrary files, potentially leading to full compromise of confidentiality, integrity, and availability of the affected system. The vulnerability is tracked as CVE-2026-38751 and has a high severity rating with a CVSS score of 7.2. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.

Join the discussion

OpenSTAManager versions prior to 2.10.2 contain an SQL Injection vulnerability in the confronta_righe.php file. The vulnerability arises because the 'righe' parameter from user input is directly concatenated into an SQL query without sanitization or validation. An authenticated attacker can exploit this to execute arbitrary SQL commands, potentially accessing sensitive data such as user credentials, customer information, and invoice data. This vulnerability has a high severity rating with a CVSS score of 8.8. The issue is fixed in version 2.10.

Join the discussion

OpenSTAManager versions prior to 2.10.2 contain a SQL injection vulnerability in the Aggiornamenti (Updates) module. This module accepts a JSON array of SQL statements via POST and executes them directly on the database without validation or sanitization. An authenticated user with access to this module can execute arbitrary SQL commands, including destructive operations like DROP or ALTER. The vulnerability disables foreign key checks before execution, increasing the risk of database integrity compromise. This issue is patched in version 2.10.2.

Join the discussion

OpenSTAManager versions prior to 2.10.2 contain a high-severity SQL Injection vulnerability in multiple AJAX select handlers. The vulnerability arises from unsanitized user input in the options[stato] GET parameter, which is directly concatenated into SQL WHERE clauses. An authenticated attacker can exploit this to perform time-based blind SQL injection, potentially extracting sensitive data such as usernames, password hashes, and financial records. This issue has been fixed in version 2.10.2.

Join the discussion

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permissions = true). It loads a record from the zz_oauth2 table using the attacker-controlled GET parameter state, and during the OAuth2 configuration flow calls unserialize() on the access_token field without any class restriction. This issue has been patched in version 2.10.2.

Join the discussion

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account (e.g.agent) into the Amministratori group as well as demote any user including existing administrators.

Join the discussion

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contains Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the righe GET parameter before reflecting it in HTML output.The $_GET['righe'] parameter is directly echoed into the HTML value attribute without any sanitization using htmlspecialchars() or equivalent functions. This allows an attacker to break out of the attribute context and inject arbitrary HTML/JavaScript.

Join the discussion

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.

Join the discussion

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling the componenti operation. An authenticated attacker can inject malicious SQL code through the options[matricola] parameter.

Join the discussion

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an authenticated SQL injection vulnerability in OpenSTAManager's Scadenzario (Payment Schedule) print template allows any authenticated user to extract sensitive data from the database, including admin credentials, customer information, and financial records. The vulnerability exists in templates/scadenzario/init.php, where the id_anagrafica parameter is directly concatenated into an SQL query without proper sanitization. The vulnerability enables complete database read access through error-based SQL injection techniques.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Package: pkg:github/devcode-it/openstamanager
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses