CVE 8.7 HIGH

OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)_CVE-2025-69213

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists in the ajax_complete.php endpoint when handling the get_sedi operation. An authenticated attacker can inject malicious SQL code through the idanagrafica parameter, leading to unauthorized database access. At time of publication, no known patch exists.

Basic Information

ID CVE-2025-69213
Source GitHub_M
Published Feb 4, 2026 at 17:42

Affected Product

Vendor devcode-it
Product openstamanager
Version <= 2.9.8
Affected Versions devcode-it openstamanager <= 2.9.8

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.