Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-247v-7cw6-q57v | OpenSTAManager affected by unauthenticated privilege escalation via modules/utenti/actions.php |
Thu, 05 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:* |
Wed, 04 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devcode
Devcode openstamanager |
|
| Vendors & Products |
Devcode
Devcode openstamanager |
Tue, 03 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators. | |
| Title | Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-04T21:21:34.908Z
Reserved: 2026-02-17T03:08:23.489Z
Link: CVE-2026-27012
Updated: 2026-03-04T21:21:29.580Z
Status : Analyzed
Published: 2026-03-03T22:16:28.833
Modified: 2026-03-05T18:19:03.887
Link: CVE-2026-27012
No data.
OpenCVE Enrichment
Updated: 2026-04-17T13:30:19Z
Github GHSA