CVE-2026-28805General(devcode / openstamanager)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch devcode openstamanager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection through the options[stato] GET parameter. The user-supplied value is read from $superselect['stato'] and concatenated directly into SQL WHERE clauses as a bare expression, without any sanitization, parameterization, or allowlist validation. An authenticated attacker can inject arbitrary SQL statements to extract sensitive data from the database, including usernames, password hashes, financial records, and any other information stored in the MySQL database. This issue has been patched in version 2.10.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openstamanager

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-02); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openstamanager

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-05: 1Mentions · 2026-04-07: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-05: 104-0204-0504-07
Signal classification3 categories
General
250.0%
Patch
125.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-022
General1Patch1
2026-04-051
Disclosure1
2026-04-071
General1
Full discourse4 posts
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-28805 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-28805

    Post summary

    The content lists a CVE identifier and its CVSS score, linking only to the NVD page without additional details or actionable information.

    1000019
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28805 - High OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Ba... https://www.thehackerwire.com/vulnerability/CVE-2026-28805/ https://t.co/n0aXqu3ooh

    Post summary

    The tweet announces a high‑severity CVE‑2026‑28805 affecting OpenSTAManager before version 2.10.2, noting a time‑based AJAX handler flaw, but gives no PoC, exploit code, active‑exploitation evidence, or patch information.

    0000068
    161 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28805 OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager … https://www.cve.org/CVERecord?id=CVE-2026-28805

    Post summary

    The snippet only lists the CVE ID and a brief, incomplete description, with no evidence of PoC, exploit, active use, or patching information.

    00000116
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28805: HIGH] OpenSTAManager software version prior to 2.10.2 is vulnerable to Time-Based Blind SQL Injection. Attackers could exploit this to access sensitive data. Update to version 2.10.2 to patc...#cve,CVE-2026-28805,#cybersecurity https://cvefind.com/CVE-2026-28805

    Post summary

    CVE‑2026‑28805 is a high‑severity time‑based blind SQL injection affecting OpenSTAManager versions prior to 2.10.2, and the recommended mitigation is to upgrade to 2.10.2.

    0000038
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdevcodeopenstamanager---

Explore more