OpenSTAManager Privilege Escalation and Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing privilege escalation and authentication bypass has been identified in OpenSTAManager versions through 2.9.8. This issue allows attackers to arbitrarily change a user's group by directly accessing 'modules/utenti/actions.php', which processes sensitive information without any authentication or authorization checks. As a result, an attacker could promote a user to the 'Amministratori' group or demote any user, including administrators.

Impact

Exploitation of this vulnerability allows an unauthenticated attacker to gain administrator privileges for any user, potentially leading to a full compromise of the application.

Reproduction

To reproduce this vulnerability, send a POST request to 'modules/utenti/actions.php' without any authentication or cookies. Include the 'op' parameter with a value that triggers the user update action, and specify the target user's ID and the desired group assignment. The changes will be reflected in the database and the administrator panel, demonstrating the successful exploitation of the vulnerability.

Added: Mar 3, 2026, 10:50 PM
Updated: Mar 3, 2026, 10:50 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.0
remediation
0.0
relevance
3.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.