Loading...
Skip to main content

CVE-2025-65103

HIGH

OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter

Published November 19, 2025Updated November 20, 2025Source: osv

Summary

### Summary An authenticated SQL Injection vulnerability in the API allows any user, regardless of permission level, to execute arbitrary SQL queries. By manipulating the `display` parameter in an API request, an attacker can exfiltrate, modify, or delete any data in the database, leading to a full system compromise. ### Details The vulnerability is located in the `retrieve()` method within `src/API/Manager.php`. User input from the `display` GET parameter is processed without proper validation. The code strips the surrounding brackets `[]`, splits the string by commas, and then passes each resulting element directly into the `selectRaw()` function of the query builder. ```php // User input from 'display' is taken without sanitization. $select = !empty($request['display']) ? explode(',', substr((string) $request['display'], 1, -1)) : null; // ... // The unsanitized input is passed directly to `selectRaw()`. foreach ($select as $s) { $query->selectRaw($s); } ``` Since `selectRaw()` is designed to execute raw SQL expressions, it executes any malicious SQL code provided in the `display` parameter. ### PoC 1. Log in to an OpenSTAManager instance as any user. 2. Navigate to the user's profile page to obtain their personal API Token. 3. Use this API token to send a specially crafted GET request to the API endpoint. **Time-Based Blind Injection Test:** Replace `<your_host>`, `<your_token>`, and `<resource_name>` with your actual values. `anagrafiche` is a valid resource. ```bash curl "http://<your_host>/openstamanager/api?token=<your_token>&resource=anagrafiche&display=[1,SLEEP(5)]" ``` The server will delay its response by approximately 5 seconds, confirming the `SLEEP(5)` command was executed by the database. ### Impact This is a critical SQL Injection vulnerability. Any authenticated user, even those with the lowest privileges, can exploit this vulnerability to: * **Exfiltrate all data** from the database (e.g., user credentials, customer information, invoices, internal data). * **Modify or delete data**, compromising data integrity. * Potentially achieve further system compromise, depending on the database user's privileges and system configuration.

Remediation

Upgrade to the fixed version using your package manager.

Composer
Update devcode-it/openstamanager to 2.9.5 or later
composer require "devcode-it/openstamanager:^2.9.5"

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (1)

PackageEcosystemAffectedFixed In
devcode-it/openstamanager
packagist
2.3.0, v2.4, v2.4.1, v2.4.10 (+79 more)2.9.5

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 8.8 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Frequently Asked Questions

What is CVE-2025-65103?
OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter This vulnerability has been assigned a severity rating of HIGH (CVSS score: 8.8/10).
How do I check if my project is affected by CVE-2025-65103?
CVE-2025-65103 affects devcode-it/openstamanager. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-65103 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
8.8

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-2jm2-2p35-rp3j

Related CVEs

  • CVE-2026-27012
    CRITICAL

    OpenSTAManager affected by unauthenticated privilege escalation via modules/utenti/actions.php

  • CVE-2025-69212
    CRITICAL

    OpenSTAManager has an OS Command Injection in P7M File Processing

  • CVE-2026-35168
    HIGH

    OpenSTAManager: SQL Injection via Aggiornamenti Module

  • CVE-2026-28805
    HIGH

    OpenSTAManager has a Time-Based Blind SQL Injection via `options[stato]` Parameter

  • CVE-2026-24417
    HIGH

    OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

  • CVE-2026-24419
    HIGH

    OpenSTAManager has a SQL Injection in the Prima Nota module

  • CVE-2026-24418
    HIGH

    OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module

  • CVE-2026-35470
    HIGH

    OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies