PT-2025-47519 · Unknown · Openstamanager

CVE-2025-65103

·

Published

2025-11-19

·

Updated

2025-11-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSTAManager versions prior to 2.9.5
Description OpenSTAManager is a management software for technical assistance and invoicing. A SQL Injection flaw exists in the API that allows authenticated users to execute arbitrary SQL queries, regardless of their permission level. By manipulating the display parameter in an API request, an attacker can potentially exfiltrate, modify, or delete data from the database, potentially leading to a full system compromise.
Recommendations Update to version 2.9.5 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65103
GHSA-2JM2-2P35-RP3J

Affected Products

Openstamanager