OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerability in the API allows any user, regardless of permission level, to execute arbitrary SQL queries. By manipulating the display parameter in an API request, an attacker can exfiltrate, modify, or delete any data in the database, leading to a full system compromise. This issue has been patched in version 2.9.5.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2jm2-2p35-rp3j OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 19 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
Description OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerability in the API allows any user, regardless of permission level, to execute arbitrary SQL queries. By manipulating the display parameter in an API request, an attacker can exfiltrate, modify, or delete any data in the database, leading to a full system compromise. This issue has been patched in version 2.9.5.
Title OpenSTAManager has an authenticated SQL Injection vulnerability in API via 'display' parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-19T20:31:35.423Z

Reserved: 2025-11-17T20:55:34.693Z

Link: CVE-2025-65103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-19T20:15:54.107

Modified: 2025-11-19T20:15:54.107

Link: CVE-2025-65103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.