Medium severity6.5NVD Advisory· Published Feb 6, 2026· Updated Jun 17, 2026
CVE-2026-24416
CVE-2026-24416
Description
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the article pricing completion handler. The application fails to properly sanitize the idarticolo parameter before using it in SQL queries, allowing attackers to inject arbitrary SQL commands and extract sensitive data through time-based Boolean inference.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
devcode-it/openstamanagerPackagist | <= 2.9.8 | — |
Affected products
3<= 2.9.8+ 1 more
- (no CPE)range: <= 2.9.8
- cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:*range: <=2.9.8
Patches
Vulnerability mechanics
References
3- github.com/devcode-it/openstamanager/security/advisories/GHSA-p864-fqgv-92q4nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-p864-fqgv-92q4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-24416ghsaADVISORY
News mentions
0No linked articles in our index yet.