CVE-2025-69212
HIGHOpenSTAManager < 2.9.8 - Authenticated OS Command Injection via P7M Filename
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-69212. PoCs published by lukasz-rybak.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2025-69212, demonstrating an OS command injection vulnerability in OpenSTAManager's P7M file processing. The exploit leverages a malicious filename in a ZIP archive to execute arbitrary commands via the `exec()` function.
Description
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2025-69212, demonstrating an OS command injection vulnerability in OpenSTAManager's P7M file processing. The exploit leverages a malicious filename in a ZIP archive to execute arbitrary commands via the `exec()` function.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H