Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-24417. PoCs published by lukasz-rybak.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-24417, a Time-Based Blind SQL Injection vulnerability in OpenSTAManager v2.9.8. It includes root cause analysis, affected code paths, and proof-of-concept steps for verification and data extraction.
Description
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the global search functionality. The application fails to properly sanitize the term parameter before using it in SQL LIKE clauses across multiple module-specific search handlers, allowing attackers to inject arbitrary SQL commands and extract sensitive data through time-based Boolean inference.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2026-24417, a Time-Based Blind SQL Injection vulnerability in OpenSTAManager v2.9.8. It includes root cause analysis, affected code paths, and proof-of-concept steps for verification and data extraction.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N