Sploitus

Exploit for OS Command Injection in Devcode Openstamanager

githubexploit · 2026-08-21

Exploit Code

README15 lines
## https://sploitus.com/exploit?id=39DE119C-3F7A-5EB6-915A-EDBD561DB43A
# CVE-2025-69212 - OpenSTAManager P7M Command Injection Exploit

A fully automated exploit script for **CVE-2025-69212**, a command injection vulnerability in OpenSTAManager. This script authenticates with admin credentials, deploys a malicious PHP web shell via a crafted P7M file in a ZIP archive, and provides command execution or a reverse shell.

## Features
- Automated authentication.
- Malicious ZIP generation and upload (`invoice.p7m` injection).
- Base64 command wrapping to prevent special character issues.
- Reverse shell and single-command execution arguments.

## Usage

```bash
python3 exploit.py -u  -U  -P  -r