CVE-2025-69212

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:00

Type Values Removed Values Added
Summary
  • (es) OpenSTAManager es un software de gestión de código abierto para asistencia técnica y facturación. En la versión 2.9.8 y anteriores, existe una vulnerabilidad crítica de inyección de comandos del sistema operativo en la funcionalidad de decodificación de archivos P7M (XML firmado). Un atacante autenticado puede cargar un archivo ZIP que contenga un archivo .p7m con un nombre de archivo malicioso para ejecutar comandos arbitrarios del sistema en el servidor.

09 Feb 2026, 21:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Devcode openstamanager
Devcode
CPE cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:*
References () https://github.com/devcode-it/openstamanager/security/advisories/GHSA-25fp-8w8p-mx36 - () https://github.com/devcode-it/openstamanager/security/advisories/GHSA-25fp-8w8p-mx36 - Exploit, Vendor Advisory

06 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 19:16

Updated : 2026-06-17 10:00


NVD link : CVE-2025-69212

Mitre link : CVE-2025-69212

CVE.ORG link : CVE-2025-69212


JSON object : View

Products Affected

devcode

  • openstamanager
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')