
CVE-2026-28805 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-28805
Post summary
The content lists a CVE identifier and its CVSS score, linking only to the NVD page without additional details or actionable information.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection through the options[stato] GET parameter. The user-supplied value is read from $superselect['stato'] and concatenated directly into SQL WHERE clauses as a bare expression, without any sanitization, parameterization, or allowlist validation. An authenticated attacker can inject arbitrary SQL statements to extract sensitive data from the database, including usernames, password hashes, financial records, and any other information stored in the MySQL database. This issue has been patched in version 2.10.2.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-04-02 | 2 | General1Patch1 |
| 2026-04-05 | 1 | Disclosure1 |
| 2026-04-07 | 1 | General1 |

CVE-2026-28805 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-28805
Post summary
The content lists a CVE identifier and its CVSS score, linking only to the NVD page without additional details or actionable information.

🟠 CVE-2026-28805 - High OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Ba... https://www.thehackerwire.com/vulnerability/CVE-2026-28805/ https://t.co/n0aXqu3ooh
Post summary
The tweet announces a high‑severity CVE‑2026‑28805 affecting OpenSTAManager before version 2.10.2, noting a time‑based AJAX handler flaw, but gives no PoC, exploit code, active‑exploitation evidence, or patch information.

CVE-2026-28805 OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager … https://www.cve.org/CVERecord?id=CVE-2026-28805
Post summary
The snippet only lists the CVE ID and a brief, incomplete description, with no evidence of PoC, exploit, active use, or patching information.

[CVE-2026-28805: HIGH] OpenSTAManager software version prior to 2.10.2 is vulnerable to Time-Based Blind SQL Injection. Attackers could exploit this to access sensitive data. Update to version 2.10.2 to patc...#cve,CVE-2026-28805,#cybersecurity https://cvefind.com/CVE-2026-28805
Post summary
CVE‑2026‑28805 is a high‑severity time‑based blind SQL injection affecting OpenSTAManager versions prior to 2.10.2, and the recommended mitigation is to upgrade to 2.10.2.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | devcode | openstamanager | - | - | - |