CVE-2025-69212 - CVE House
Back to Database
Status published Critical CVE-2025-69212

OpenSTAManager has an OS Command Injection in P7M File Processing

Vulnerability Description

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69212

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

openstamanager
Vulnerable Versions:
<= 2.9.8

Timeline

Official Publish: February 6th, 2026
Last Modified: February 9th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)