SQL Injection Vulnerability in OpenSTAManager by Devcode It
CVE-2025-69214
8.7HIGH
What is CVE-2025-69214?
An SQL Injection flaw affects OpenSTAManager up to version 2.9.8, enabling authenticated attackers to execute arbitrary SQL commands via the options[matricola] parameter in the ajax_select.php endpoint. This vulnerability may allow attackers to access sensitive data, manipulate database queries, and execute unauthorized actions within the application.
Affected Version(s)
openstamanager <= 2.9.8
