CVE-2025-69213 | devcode-it openstamanager up to 2.9.8 ajax_complete.php get_sedi idanagrafica sql injection (GHSA-w995-ff8h-rppg)
A vulnerability categorized as critical has been discovered in devcode-it openstamanager up to 2.9.8. This vulnerability affects the function get_sedi of the file ajax_complete.php. Executing a manipulation of the argument idanagrafica can lead to sql injection.
This vulnerability is registered as CVE-2025-69213. It is possible to launch the attack remotely. No exploit is available.