CVE-2026-24416
- EPSS 0.01%
- Veröffentlicht 06.02.2026 18:08:44
- Zuletzt bearbeitet 09.02.2026 21:44:51
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the article pricing completion handler. The application ...
CVE-2026-24417
- EPSS 0.01%
- Veröffentlicht 06.02.2026 18:07:52
- Zuletzt bearbeitet 09.02.2026 21:43:49
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the global search functionality. The application fails t...
CVE-2026-24418
- EPSS 0.01%
- Veröffentlicht 06.02.2026 18:06:47
- Zuletzt bearbeitet 09.02.2026 21:42:38
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Sche...
CVE-2025-69215
- EPSS 0.04%
- Veröffentlicht 04.02.2026 17:42:31
- Zuletzt bearbeitet 18.02.2026 15:16:10
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability in the Stampe Module. At time of publication, no known patch exists.
CVE-2025-69213
- EPSS 0.04%
- Veröffentlicht 04.02.2026 17:42:28
- Zuletzt bearbeitet 18.02.2026 15:16:41
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists in the ajax_complete.php endpoint when handling the get_sedi operation. An authenticated att...
CVE-2023-38878
- EPSS 0.07%
- Veröffentlicht 11.09.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:20
A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execute arbitrary JavaScript in the web browser of a victim by injecting a malicious payload into the 'error' and ...