Back to Database
Status published
High
CVE-2025-69215
OpenSTAManager has an SQL Injection in the Stampe Module
Vulnerability Description
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability in the Stampe Module. At time of publication, no known patch exists.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69215
Credits & Attribution
No credits recorded in the NVD database.
More from devcode-it
View All →CVE-2025-69216
OpenSTAManager has an SQL Injection in Scadenzario Print Template
High
8.7
CVE-2025-69214
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
High
8.7
CVE-2025-69213
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
High
8.7
CVE-2025-69212
OpenSTAManager has an OS Command Injection in P7M File Processing
Critical
9.4
CVE-2025-65103
OpenSTAManager has an authenticated SQL Injection vulnerability in API via 'display' parameter
High
8.8
Affected Vendor
devcode-it
View all reports →Affected Software
openstamanager
Vulnerable Versions:
<= 2.9.8
Timeline
Official Publish:
February 4th, 2026
Last Modified:
February 4th, 2026
Added to House:
July 22nd, 2026