PT-2025-47519 · Unknown · Openstamanager

Published

2025-11-19

·

Updated

2025-11-21

·

CVE-2025-65103

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSTAManager versions prior to 2.9.5
Description OpenSTAManager is a management software for technical assistance and invoicing. A SQL Injection flaw exists in the API that allows authenticated users to execute arbitrary SQL queries, regardless of their permission level. By manipulating the display parameter in an API request, an attacker can potentially exfiltrate, modify, or delete data from the database, potentially leading to a full system compromise.
Recommendations Update to version 2.9.5 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-65103
GHSA-2JM2-2P35-RP3J

Affected Products

Openstamanager