HIGH
Open STA Manager 2.3 Arbitrary File Download via Path Traversal
Published May 30, 2026
7.1
HIGHCVSS 4.0
EPSS 0.33%
Description
Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send GET requests to modules/backup/actions.php with op=getfile and traverse directories using ../ sequences to access sensitive system files.
Affected products
-
- Version 2.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Openstamanager | Open STA Manager | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://www.openstamanager.com/ product
- https://sourceforge.net/projects/openstamanager/files/latest/download product
- https://www.exploit-db.com/exploits/45693 exploit
- https://www.vulncheck.com/advisories/open-sta-manager-arbitrary-file-download-via-path-traversal third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openstamanager.com/ | product | |
| https://sourceforge.net/projects/openstamanager/files/latest/download | product | |
| https://www.exploit-db.com/exploits/45693 | exploit | |
| https://www.vulncheck.com/advisories/open-sta-manager-arbitrary-file-download-via-path-traversal | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 30, 2026
Updated Jul 15, 2026
Reserved May 30, 2026
Link CVE-2018-25421
CISA Vulnrichment
Updated Jun 1, 2026