High severityNVD Advisory· Published Feb 6, 2026· Updated Feb 9, 2026
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
CVE-2026-24416
Description
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the article pricing completion handler. The application fails to properly sanitize the idarticolo parameter before using it in SQL queries, allowing attackers to inject arbitrary SQL commands and extract sensitive data through time-based Boolean inference.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
devcode-it/openstamanagerPackagist | <= 2.9.8 | — |
Affected products
2- Range: <= 2.9.8
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-p864-fqgv-92q4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-24416ghsaADVISORY
- github.com/devcode-it/openstamanager/security/advisories/GHSA-p864-fqgv-92q4ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.