High severity8.8OSV Advisory· Published Nov 19, 2025· Updated Apr 15, 2026
CVE-2025-65103
CVE-2025-65103
Description
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerability in the API allows any user, regardless of permission level, to execute arbitrary SQL queries. By manipulating the display parameter in an API request, an attacker can exfiltrate, modify, or delete any data in the database, leading to a full system compromise. This issue has been patched in version 2.9.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
devcode-it/openstamanagerPackagist | < 2.9.5 | 2.9.5 |
Affected products
2- Range: v2.3-beta.1, v2.3-beta.2, v2.4, …
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.