CVE-2025-69212
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.
- Affected products
- Fatturaelettronica, Openstamanager, Importfe Zip
- Devcode Openstamanager
- ≤ 2.9.8
- Fix
- Available
- CVSS 4.0
- 9.4 CRITICAL
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.8% (76th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2026-02-06
CVE-2025-69212 at NVD
13 known exploits for CVE-2025-69212
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for OS Command Injection in Devcode Openstamanager
Exploit for CVE-2026-69212
Exploit for OS Command Injection in Devcode Openstamanager
📄 OpenSTAManager 2.9.8 Command Injection
Exploit for OS Command Injection in Devcode Openstamanager