📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2025-69214

High ⚡ Exploit Available
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling t
CWE-89 — Weakness Type
Published: Feb 6, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling the componenti operation. An authenticated attacker can inject malicious SQL code through the options[matricola] parameter.

🤖 AI Executive Summary

OpenSTAManager versions 2.9.8 and earlier contain a critical SQL Injection vulnerability in the ajax_select.php endpoint that allows authenticated attackers to execute arbitrary SQL commands through the options[matricola] parameter. This vulnerability poses significant risk to organizations using OpenSTAManager for technical assistance and invoicing operations. Immediate patching is required as exploits are publicly available.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 22, 2026 06:13
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations in the following sectors are at elevated risk: (1) Government agencies and municipalities using OpenSTAManager for technical support and asset management; (2) Healthcare facilities managing maintenance and invoicing operations; (3) Telecommunications providers (STC, Mobily, Zain) for technical support systems; (4) Financial institutions and accounting firms using the invoicing module; (5) Manufacturing and industrial companies managing technical assistance. The vulnerability allows authenticated users to bypass database security controls, potentially leading to unauthorized data access, modification, or deletion of sensitive business records, financial data, and customer information.
🏢 Affected Saudi Sectors
Government and Public Administration Healthcare and Medical Services Telecommunications Financial Services and Banking Manufacturing and Industrial Accounting and Professional Services Utilities and Energy
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all instances of OpenSTAManager running version 2.9.8 or earlier across your organization
2. Restrict access to ajax_select.php endpoint to trusted IP addresses only using WAF or network controls
3. Review access logs for suspicious SQL patterns in the options[matricola] parameter
4. Implement input validation and parameterized queries at the application level

PATCHING:
1. Upgrade OpenSTAManager to version 2.9.9 or later immediately
2. Test patches in a staging environment before production deployment
3. Verify patch application by checking version numbers and reviewing changelog

COMPENSATING CONTROLS (if immediate patching not possible):
1. Implement Web Application Firewall (WAF) rules to block SQL injection patterns in ajax_select.php
2. Apply database-level restrictions: use least-privilege database accounts, disable dangerous functions (LOAD_FILE, INTO OUTFILE)
3. Enable SQL query logging and monitoring for anomalous patterns
4. Implement rate limiting on ajax_select.php endpoint

DETECTION:
1. Monitor for SQL keywords in options[matricola] parameter: UNION, SELECT, DROP, INSERT, UPDATE, DELETE, EXEC, SCRIPT
2. Alert on multiple failed database queries from single user session
3. Track unusual database activity patterns during business hours
4. Log all authentication events to ajax_select.php endpoint
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع نسخ OpenSTAManager التي تعمل بالإصدار 2.9.8 أو أقدم عبر المنظمة
2. تقييد الوصول إلى نقطة نهاية ajax_select.php للعناوين الموثوقة فقط باستخدام جدار الحماية أو عناصر التحكم في الشبكة
3. مراجعة سجلات الوصول للأنماط المريبة في معامل options[matricola]
4. تطبيق التحقق من صحة المدخلات والاستعلامات المعاملة على مستوى التطبيق

تطبيق التصحيحات:
1. ترقية OpenSTAManager إلى الإصدار 2.9.9 أو أحدث فوراً
2. اختبار التصحيحات في بيئة التجريب قبل نشرها في الإنتاج
3. التحقق من تطبيق التصحيح بفحص أرقام الإصدارات ومراجعة السجل

عناصر التحكم البديلة (إذا لم يكن الترقية الفورية ممكنة):
1. تطبيق قواعد جدار حماية تطبيقات الويب لحجب أنماط حقن SQL في ajax_select.php
2. تطبيق القيود على مستوى قاعدة البيانات: استخدام حسابات قاعدة البيانات ذات الامتيازات الأقل، تعطيل الوظائف الخطرة
3. تفعيل تسجيل الاستعلامات والمراقبة لأنماط غير عادية
4. تطبيق تحديد معدل على نقطة نهاية ajax_select.php

الكشف:
1. مراقبة كلمات SQL في معامل options[matricola]: UNION, SELECT, DROP, INSERT, UPDATE, DELETE
2. التنبيه على استعلامات قاعدة البيانات الفاشلة المتعددة من جلسة مستخدم واحدة
3. تتبع أنماط نشاط قاعدة البيانات غير العادية
4. تسجيل جميع أحداث المصادقة إلى نقطة نهاية ajax_select.php
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.14.2.1 - Secure development policy and procedures A.14.2.5 - Secure development environment A.12.6.1 - Management of technical vulnerabilities A.12.2.1 - Monitoring and logging of access to information
🔵 SAMA CSF
ID.RA-1 - Asset management and vulnerability identification PR.DS-6 - Data integrity and protection DE.CM-1 - Detection and analysis of anomalies RS.RP-1 - Response planning and procedures
🟡 ISO 27001:2022
A.12.2.1 - User access logging and monitoring A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy A.14.2.5 - Secure development environment
🟣 PCI DSS v4.0.1
6.2 - Security patches and updates 6.5.1 - Injection flaws prevention 10.2 - User access logging 11.2 - Vulnerability scanning
📦 Affected Products / CPE 1 entries
devcode:openstamanager
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-89
EPSS0.01%
Exploit ✓ Yes
Patch ✓ Yes
Published 2026-02-06
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-89
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.