CVE-2025-65103

HIGH

Devcode-it Openstamanager < 2.9.5 - SQL Injection

Title source: rule
STIX 2.1

Description

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerability in the API allows any user, regardless of permission level, to execute arbitrary SQL queries. By manipulating the display parameter in an API request, an attacker can exfiltrate, modify, or delete any data in the database, leading to a full system compromise. This issue has been patched in version 2.9.5.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0001
EPSS Percentile 1.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
devcode-it/openstamanager 0 - 2.9.5Packagist
devcode-it/openstamanager < 2.9.5
Published Nov 19, 2025
Tracked Since Feb 18, 2026