Feed/CVE-2025-69212
CVE-2025-69212HIGHCVSS 8.8

CVE-2025-69212

Published Feb 6, 2026·Updated Jun 17, 2026

NVD Description

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.

Public Exploits & PoCs11 found

[POC] GHSA-2j8v-hwgc-x698 — CVE-2025-69212-PoC

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

1

PoC: CVE-2026-69212

Python poc, exploit for CVE-2025-69212

1

[POC] GHSA-2j8v-hwgc-x698 — CVE-2025-69212

CVE-2025-69212 Proof-of-concept.

[POC] GHSA-2j8v-hwgc-x698 — CVE-2025-69212-PoC

CVE-2025-69212 - OpenSTAManager OS Command Injection PoC

[POC] MAL-2026-2307 — CVE-2025-69212-Authenticated-RCE-PoC

Automated PoC for CVE-2025-69212 - OpenSTAManager <=2.9.8 authenticated RCE

PoC: CVE-2025-69212-Exploit

A fully automated exploit script for **CVE-2025-69212**, a command injection vulnerability in OpenSTAManager. This script authenticates with admin credentials, deploys a malicious PHP web shell via a crafted P7M file in a ZIP archive, and provides command execution or a reverse shell.

PoC: OpenSTA-Exploit

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

PoC: CVE-2025-69212-for-myself

just record for myself

PoC: Hack-The-Box-Enigma-Findings-Report

HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager (CVE-2025-69212) through to root via a misconfigured OliveTin service. Full report and evidence appendix to be published once permitted by HTB's active-machine policy.

PoC: CVE-2025-69212_PoC

This repository contains a PoC exploit for CVE-2025-69212.

PoC: CVE-2025-69212

CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free