Логотип exploitDog
bind:CVE-2025-69212
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-69212

Количество 2

Количество 2

nvd логотип

CVE-2025-69212

2 дня назад

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.

EPSS: Низкий
github логотип

GHSA-25fp-8w8p-mx36

3 дня назад

OpenSTAManager has an OS Command Injection in P7M File Processing

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-69212

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.

0%
Низкий
2 дня назад
github логотип
GHSA-25fp-8w8p-mx36

OpenSTAManager has an OS Command Injection in P7M File Processing

0%
Низкий
3 дня назад

Уязвимостей на страницу