THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-crx4-7mmq-j74j (low) — OpenSTAManager has HTML Injection in modules/utenti/edit.php

[GHSA] GHSA-crx4-7mmq-j74j (low) — OpenSTAManager has HTML Injection in modules/utenti/edit.php

medgithub_advisoriesPublished 2026-08-26

GHSA-crx4-7mmq-j74j Severity: low CVE: CVE-2026-44701

OpenSTAManager has HTML Injection in modules/utenti/edit.php

### Summary An HTML Injection vulnerability exists in the user group creation functionality that allows an attacker to inject arbitrary HTML content into the application interface. The vulnerability occurs when user-supplied input in the group name field is not properly sanitized be

Indicators of compromise

Original source: https://github.com/advisories/GHSA-crx4-7mmq-j74j