SQL Injection Vulnerability in OpenSTAManager Affects Multiple Users
CVE-2025-69216
What is CVE-2025-69216?
OpenSTAManager, an open-source management tool for technical assistance and invoicing, presents an SQL injection vulnerability in versions 2.9.8 and earlier. This flaw resides in the Scadenzario (Payment Schedule) print template, specifically within templates/scadenzario/init.php. An attacker with authenticated access can exploit the vulnerability by manipulating the id_anagrafica parameter, allowing them to execute unauthorized SQL queries. This could lead to the exposure of sensitive information, including admin credentials, customer data, and financial records, through error-based techniques that facilitate complete read access to the database. The lack of proper input sanitization in the application code significantly increases the risk of data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openstamanager <= 2.9.8
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
