Junglewise Threat Intelligence

CVE-2026-38751: OpenSTAManager arbitrary file upload in module update functionality

CVE-2026-38751 · Severity: high · CVSS 7.2 · Published 2026-05-04

Technologies: Devcode-It Openstamanager. Vendors: Packagist, Devcode.

Executive brief

OpenSTAManager, an open-source business management and e-billing software, contains a security flaw in its module update system. An attacker with administrative privileges can upload malicious files to the server, potentially leading to a complete takeover of the application and its database. This could result in the theft of sensitive customer data, financial records, or a total disruption of business operations.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in OpenSTAManager versions 2.10 and earlier. The flaw is located in the 'modules/aggiornamenti/upload_modules.php' component, which handles module updates. A remote attacker with high privileges (administrative access) can exploit this by uploading a malicious PHP script or other dangerous file types. Successful exploitation allows for arbitrary code execution on the underlying server, potentially leading to full system compromise. While a proof-of-concept was referenced in initial reports, users are advised to restrict access to the update module and upgrade to a patched version if available.

Affected products

  • devcode-it OpenSTAManager up to and including 2.10

Timeline

  • 2026-05-04: disclosed
  • 2026-05-04: advisory

References

Related threats