
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69215 is an authenticated SQL Injection vulnerability in the Stampe Module of OpenSTAManager, an open-source management software for technical assistance and invoicing. The flaw affects all versions up to and including 2.9.8, and was disclosed on February 3, 2026 via a GitHub Security Advisory (GHSA-qx9p-w3vj-q24q). At the time of publication, no official patch was available. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, OSM Advisory).
The root cause is improper neutralization of SQL special elements (CWE-89) in modules/stampe/actions.php at line 26. In the update case, the module POST parameter is directly concatenated into an SQL UPDATE query — $dbo->query('UPDATE zz_prints SET predefined = 0 WHERE id_module = '.post('module')) — without using the application's prepare() sanitization function. While the predefined parameter is protected via intval(), the module parameter only undergoes an !empty() check, which provides no SQL injection protection. The vulnerability is exploitable as an error-based SQL injection using MySQL functions such as EXTRACTVALUE, UPDATEXML, and GTID_SUBSET, and a full public proof-of-concept exploit script (exploit_stampe_sqli.py) was included in the advisory (OSM Advisory).
Successful exploitation allows an authenticated attacker to extract sensitive data from the underlying MySQL database, including admin usernames, email addresses, and password hashes, as well as database version, name, and user information. The high integrity and availability impact scores indicate that an attacker could also modify or corrupt database records, potentially disrupting business operations. Because the zz_users table is accessible via injection, credential theft could enable privilege escalation or lateral movement within the application (GitHub Advisory, OSM Advisory).
A full proof-of-concept Python exploit script was publicly released alongside the advisory on February 3, 2026, making exploitation straightforward for any authenticated user with access to the Stampe module — including low-privileged users in the "Tecnici" group, not just administrators. The EPSS score is approximately 0.055% (18th percentile), suggesting low but non-negligible exploitation probability in the near term. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog. Qualys has assigned detection ID 5007363 for this vulnerability (GitHub Advisory, OSM Advisory).
https://demo.osmbusiness.it uses tecnico/tecnicotecnico./index.php with parameters username, password, and op=login to establish an authenticated session and obtain a PHPSESSID cookie.14 AND UPDATEXML(1,CONCAT(0x7e,(SELECT VERSION()),0x7e),1) for the module parameter./modules/stampe/actions.php with parameters op=update, id_record=1, predefined=1, module=[INJECTION_PAYLOAD], title=Test, filename=test.pdf using the authenticated session.~) delimiters (e.g., XPATH syntax error: '~8.3.0~').zz_users (e.g., SELECT SUBSTRING(password,1,30) FROM zz_users WHERE idgruppo=1 LIMIT 1), then crack hashes offline using tools like hashcat to gain administrative access (OSM Advisory)./modules/stampe/actions.php containing SQL function keywords (EXTRACTVALUE, UPDATEXML, GTID_SUBSET, CONCAT, 0x7e) in the module parameter; repeated requests to this endpoint from a single session in a short timeframe./modules/stampe/actions.php with abnormally long or encoded module parameter values; application error logs containing XPATH syntax error, SQLSTATE[HY000], or PDOException messages with tilde-delimited data.UPDATE zz_prints SET predefined = 0 WHERE id_module = ... queries with non-numeric or complex id_module values in MySQL query logs; queries referencing information_schema.tables or zz_users from the web application database user outside of normal application flow (OSM Advisory).As of the advisory publication date (February 3, 2026), no official patched version of OpenSTAManager was available for versions up to and including 2.9.8. Organizations should monitor the OpenSTAManager repository for a patched release and apply it immediately upon availability. As an interim workaround, restrict access to the Stampe module to only trusted administrative users, implement a web application firewall (WAF) rule to block SQL injection patterns in POST parameters targeting /modules/stampe/actions.php, and enforce network-level access controls to limit exposure of the OpenSTAManager instance. The vulnerable code in modules/stampe/actions.php line 26 should be remediated by replacing direct string concatenation with the application's prepare() parameterized query function (OSM Advisory).
The vulnerability was reported by security researcher Łukasz Rybak and published via GitHub's security advisory process. No significant vendor statements, notable researcher commentary beyond the original advisory, or major media coverage have been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."