Executive brief
OpenSTAManager, an open-source business management and e-billing software, contains a security flaw in its module update system. An attacker with administrative privileges can upload malicious files to the server, potentially leading to a complete takeover of the application and its database. This could result in the theft of sensitive customer data, financial records, or a total disruption of business operations.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in OpenSTAManager versions 2.10 and earlier. The flaw is located in the 'modules/aggiornamenti/upload_modules.php' component, which handles module updates. A remote attacker with high privileges (administrative access) can exploit this by uploading a malicious PHP script or other dangerous file types. Successful exploitation allows for arbitrary code execution on the underlying server, potentially leading to full system compromise. While a proof-of-concept was referenced in initial reports, users are advised to restrict access to the update module and upgrade to a patched version if available.
Affected products
- devcode-it OpenSTAManager up to and including 2.10
Timeline
- 2026-05-04: disclosed
- 2026-05-04: advisory