SQL Injection Vulnerability in OpenSTAManager Affects Multiple Users
CVE-2025-69216

8.7HIGH

Key Information:

Vendor

Devcode-it

Vendor
CVE Published:
6 February 2026

What is CVE-2025-69216?

OpenSTAManager, an open-source management tool for technical assistance and invoicing, presents an SQL injection vulnerability in versions 2.9.8 and earlier. This flaw resides in the Scadenzario (Payment Schedule) print template, specifically within templates/scadenzario/init.php. An attacker with authenticated access can exploit the vulnerability by manipulating the id_anagrafica parameter, allowing them to execute unauthorized SQL queries. This could lead to the exposure of sensitive information, including admin credentials, customer data, and financial records, through error-based techniques that facilitate complete read access to the database. The lack of proper input sanitization in the application code significantly increases the risk of data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

openstamanager <= 2.9.8

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.