CVE Database
/

CVE-2025-69214

Back to search

CVE-2025-69214

Published: Feb 6, 2026

Modified: Feb 9, 2026

PUBLISHED

Description

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling the componenti operation. An authenticated attacker can inject malicious SQL code through the options[matricola] parameter.

VendorProductVersions

devcode-it

openstamanager

affected
<= 2.9.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now