
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69213 is a SQL Injection vulnerability in OpenSTAManager's ajax_complete.php endpoint affecting the get_sedi operation. It was discovered by Łukasz Rybak and published on February 3, 2026, affecting all versions of OpenSTAManager up to and including 2.9.8 (devcode-it/openstamanager). An authenticated attacker can inject malicious SQL via the idanagrafica GET parameter, leading to unauthorized database access. The vulnerability carries a CVSS v4 base score of 8.7 (High) and a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, OSM Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from direct string concatenation of unsanitized user input into a SQL query. In modules/anagrafiche/ajax/complete.php (line 28), the get_sedi case retrieves $_GET['idanagrafica'] via get('idanagrafica') and concatenates it directly into a SELECT query: WHERE idanagrafica='".$idanagrafica."'. The sink $dbo->fetchArray($q) then executes the malicious query without any parameterization or escaping. Exploitation requires only a valid authenticated session (low-privilege user) and is performed over the network with no user interaction, using time-based blind SQL injection techniques (GitHub Advisory, OSM Advisory).
Successful exploitation enables complete database extraction, including user credentials, customer data, and financial records. An attacker can escalate privileges by modifying the zz_users table to gain administrative access, and can also perform unauthorized modification or deletion of database records, compromising data integrity. If MySQL file permissions allow, the vulnerability could be leveraged for Remote Code Execution via SELECT ... INTO OUTFILE, potentially enabling full server compromise (GitHub Advisory, OSM Advisory).
Proof-of-concept exploit code is publicly available in the GitHub Security Advisory, including both a manual time-based blind SQLi payload and a sqlmap command for automated exploitation. As of the time of publication, there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.058% (19th percentile), indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no specific threat actor attribution has been reported (GitHub Advisory, OSM Advisory).
PHPSESSID cookie.ajax_complete.php endpoint is accessible at http://<target>/ajax_complete.php?op=get_sedi&idanagrafica=1.GET /ajax_complete.php?op=get_sedi&idanagrafica=1' AND (SELECT 1 FROM (SELECT(SLEEP(5)))a) AND '1'='1 HTTP/1.1
Host: <target>
Cookie: PHPSESSID=<session_cookie>sqlmap -u "http://<target>/ajax_complete.php?op=get_sedi&idanagrafica=1*" \
--cookie="PHPSESSID=<session_cookie>" \
--dbms=MySQL \
--technique=T \
--level=3 \
--dumpzz_users table to grant the attacker's account administrative privileges within OpenSTAManager.SELECT ... INTO OUTFILE to write a PHP web shell to a web-accessible directory for remote code execution (GitHub Advisory, OSM Advisory)./ajax_complete.php with op=get_sedi and idanagrafica values containing SQL keywords such as SLEEP, SELECT, UNION, AND, --, or URL-encoded equivalents; repeated requests with varying idanagrafica values suggesting automated enumeration.ajax_complete.php?op=get_sedi with anomalous or lengthy idanagrafica parameter values; MySQL slow query logs showing repeated SLEEP() calls or unexpected SELECT ... INTO OUTFILE statements.shell.php, cmd.php, or random strings.zz_users table, such as new admin accounts or modified privilege fields; unexpected data exports or large result sets in query logs (GitHub Advisory, OSM Advisory).As of the advisory publication date, no official patched version of OpenSTAManager has been released — all versions up to and including 2.9.8 are affected. The recommended remediation is to replace direct SQL string concatenation with parameterized prepared statements in modules/anagrafiche/ajax/complete.php. As interim workarounds: restrict network access to the ajax_complete.php endpoint via firewall or web server rules; apply the principle of least privilege to database accounts used by OpenSTAManager; and deploy a Web Application Firewall (WAF) to detect and block SQL injection patterns targeting the idanagrafica parameter. Monitor the OpenSTAManager repository for patch releases and apply them immediately when available (GitHub Advisory, OSM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."