OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
Vulnerability Description
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling the componenti operation. An authenticated attacker can inject malicious SQL code through the options[matricola] parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69214
Credits & Attribution
No credits recorded in the NVD database.
More from devcode-it
View All →Affected Vendor
devcode-it
View all reports →