OpenSTAManager (<= 2.9.8) contains a critical OS command injection in the P7M (signed XML) file decoding workflow. During processing of an uploaded ZIP archive, a user-controlled filename from a contained .p7m entry is incorporated into a call to exec() without adequate sanitization/validation, allowing an authenticated attacker to craft a malicious filename that injects shell metacharacters and results in arbitrary command execution on the server during P7M decoding.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
11 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small, single-purpose proof-of-concept exploit for CVE-2025-69212 affecting OpenSTAManager <= 2.9.8. The repo contains three files: a license, a README with exploitation notes and examples, and one Python script (exploit.py). The Python code is minimal and only generates a malicious ZIP archive; it does not perform authentication, upload, or automated post-exploitation. The exploit abuses command injection via a crafted .p7m filename inside a ZIP archive. The filename is constructed as invoice.p7m";{cmd};echo ".p7m so that when the target application processes the .p7m entry and unsafely passes the filename into an exec()-style command, the injected shell command runs on the server. The hardcoded payload changes into the files directory and writes a PHP webshell: <?php system($_GET["c"]); ?> into SHELL.php. The README demonstrates subsequent remote command execution by browsing to /files/SHELL.php with a c query parameter. Overall, this is a valid operational PoC for authenticated file-upload-driven web RCE, with the main capability being generation of a malicious archive that leads to arbitrary command execution and webshell deployment if the vulnerable server-side processing path is reached.
This repository is a small, focused exploit PoC for CVE-2025-69212 affecting OpenSTAManager <= 2.9.8. It contains one Python exploit script and a minimal README showing reverse-shell usage. The exploit is not part of a larger framework. The Python script authenticates to OpenSTAManager using supplied credentials, then abuses an authenticated file-upload path in the invoice import workflow. The vulnerability is described in comments as a command injection in decodeP7M(), where an uploaded .p7m filename is passed into an exec()-backed openssl command inside double quotes. Because shell command substitution $(...) is still evaluated, the attacker places a base32-encoded bash payload inside the filename, avoiding slash characters that filenames cannot contain. Uploading the crafted file to /actions.php with op=save triggers execution. Capabilities include: authenticated arbitrary command execution, blind output capture by redirecting stdout/stderr to a file under the target webroot and retrieving it over HTTP, an interactive pseudo-shell that maintains a working-directory illusion by repeatedly issuing commands, and a bash reverse shell callback to an attacker-controlled host and port. The exploit assumes the target is Linux-like because it relies on /bin/sh behavior, bash, base32, setsid, and /dev/tcp. Repository structure is straightforward: CVE-2025-69212_PoC.py contains all exploit logic, including login(), fire() for the malicious upload, run_blind() for staged output retrieval, interactive() for pseudo-shell behavior, and main() for CLI parsing and mode selection. README.md only provides a sample invocation. Overall, this is a real operational authenticated RCE exploit with practical post-exploitation options rather than a detector or placeholder.
This repository is a small standalone Python proof-of-concept for CVE-2025-69212 affecting OpenSTAManager. It contains one executable script (CVE-2025-69212_PoC.py), a README, and a license file. The exploit is not part of a larger framework. The script uses requests, click, zipfile, os, and BeautifulSoup. Its workflow is: verify the target looks like an OpenSTAManager login page, authenticate with provided credentials, create a malicious ZIP archive if needed, upload that archive to the application’s actions.php endpoint, and then interact with a PHP webshell dropped under /files/SHELL.php. The exploit specifically abuses the P7M decoding/file handling path by embedding shell metacharacters in a ZIP entry name. The injected command changes into the server-side files directory and writes a PHP webshell containing system($_GET["c"]). Main capabilities: - Authenticated login to the target via /?op=login - Delivery of a crafted ZIP archive to /actions.php - Triggering OS command injection through the vulnerable P7M processing workflow - Persistence of a simple PHP webshell at /files/SHELL.php - Arbitrary command execution by passing commands in the c query parameter Notable implementation details: - The script treats HTTP 500 from the upload request as a success indicator that the exploit was processed. - It also treats HTTP 500 from GET /files/SHELL.php as evidence the shell is already present. - The exploit requires valid credentials, so this is authenticated RCE rather than unauthenticated exploitation. - The payload is basic and hardcoded, making the repository best classified as OPERATIONAL rather than fully weaponized. Overall, this is a real exploit PoC for authenticated remote command execution against vulnerable OpenSTAManager instances, with a straightforward end-to-end chain from login to webshell deployment and command execution.
Repository contains a small standalone Python proof-of-concept for CVE-2025-69212 affecting OpenSTAManager <= 2.9.8. Structure is minimal: a README describing the vulnerability and usage, and a single executable script exploit.py implementing the full attack chain. The exploit is authenticated and targets a vulnerable ZIP upload/import path. It first logs in to the application via /?op=login using supplied credentials, extracts the PHPSESSID cookie, then builds a local malicious archive named exploit.zip. Inside that archive it places an empty .p7m entry whose filename is crafted to break into shell execution and run a command that writes a PHP webshell: <?php system($_GET["cmd"]); ?>. The script uploads the archive to /actions.php with parameters op=save, id_module=14, and id_plugin=48, expecting a 500 response as an indicator that the vulnerable processing path was hit. It then probes for the generated webshell at a random numeric filename in the web root and, if the user supplied --cmd, invokes the shell with ?cmd=. Main capability is authenticated remote code execution with persistence in the form of a web-accessible PHP shell. The code is operational rather than a mere detector because it performs login, payload generation, upload, verification, and command execution end-to-end.
This repository is a small, focused Python proof-of-concept exploit for CVE-2025-69212 affecting OpenSTAManager. The repo contains three files: a README with usage examples, a requirements.txt listing requests, and a single executable script, cve-2025-69212_poc.py, which is the main exploit entry point. The exploit targets an authenticated OS command injection in OpenSTAManager's P7M file processing workflow. It logs into the web application using supplied credentials, then uploads a crafted ZIP archive to /actions.php with parameters op=save, id_module, and id_plugin. The ZIP contains a .p7m file whose filename is intentionally malformed to break out of a quoted openssl smime exec() invocation and append arbitrary shell commands. This yields remote command execution as the web server user. Operationally, the script supports two modes: a one-shot command execution mode that redirects output to files/pwn_out.txt and then fetches it over HTTP, and a persistence mode that writes a PHP webshell to files/shell.php and verifies it by invoking ?c=id. If the expected output path is wrong, the script probes several fallback web paths such as /uploads/, /allegati/, /files/fatture/, and /files/importFE/. The exploit is not part of a larger framework. It is more than a bare PoC because it automates authentication, payload construction, upload, output retrieval, and fallback discovery, but its payloading is still basic and hardcoded, making OPERATIONAL the best maturity fit.
This repository is a small standalone exploit project with 3 files: LICENSE, README.md, and a single Python entry point, exploit.py. It targets CVE-2025-69212 in OpenSTAManager <= 2.9.8, an authenticated OS command injection in P7M file processing. The exploit abuses the vulnerable XML::decodeP7M() path by uploading a ZIP archive containing a .p7m file whose filename injects shell metacharacters into an exec() call. The Python script is an operational exploit rather than a simple detector. Based on the visible code and README, its workflow is: establish an authenticated session using either username/password or an existing PHPSESSID cookie; optionally scrape a login token from /index.php; auto-detect relevant module/plugin IDs if not supplied; upload a crafted ZIP payload to the vulnerable import functionality; then perform one or more post-exploitation actions. Supported actions include vulnerability verification (--check), blind command execution (--cmd), PHP webshell deployment (--webshell), interactive command execution through the deployed webshell (--rce), and reverse shell triggering (--reverse-shell) using python, nc, or nc-e methods. The exploit is clearly aimed at web application RCE over HTTP(S). It includes practical operator features such as proxy support, SSL verification disabling, request throttling/delay, session reuse, and plugin/module auto-detection. The README also documents an important exploitation constraint: injected commands must avoid forward slashes because ZIP extraction semantics would split filenames into directories, breaking the payload. Overall, this is a credible standalone authenticated RCE exploit with usable post-exploitation capabilities, not merely a proof-of-concept or scanner.
This repository is a small, single-purpose Python proof-of-concept exploit for CVE-2025-69212. It contains one executable code file, CVE-2025-69212.py, and a README with usage instructions. The script is not part of a larger exploit framework. The exploit performs authenticated remote code execution against a vulnerable web application by abusing unsafe handling of uploaded .p7m filenames inside a ZIP archive. In create_malicious_zip(), it builds exploit.zip containing a crafted filename: invoice.p7m";cd files && echo '<?php system($_GET["c"]); ?>' > SHELL.php;echo ".p7m. The apparent goal is to break out of a shell command used by the server-side P7M decoding routine and execute arbitrary shell commands on the server. The injected command changes into the files directory and writes a PHP webshell named SHELL.php. In exploit(), the script uploads exploit.zip to the target's /actions.php endpoint using multipart/form-data with query parameters op=aggiungi-allegato, id_module=71, and id_record=1. A valid PHPSESSID cookie is required, so this is an authenticated exploit rather than an unauthenticated one. After successful upload, the script enters an interactive loop. In execute_command(), it sends HTTP GET requests to /files/SHELL.php with the c parameter set to the operator's command. The PHP payload executes system($_GET["c"]), returning command output in the HTTP response body. This gives the attacker a basic interactive webshell for arbitrary command execution. Overall, the repository structure is minimal and clearly malicious in intent: generate a crafted archive, upload it to a vulnerable endpoint, plant a PHP webshell, and use that webshell for interactive command execution. The exploit is operational because it includes a working payload and post-exploitation command channel, but it is not heavily modular or framework-integrated.
Small standalone Python PoC repository for CVE-2025-69212 targeting OpenSTAManager <= 2.9.8. Repository contains one executable exploit script (exploit.py), a README describing the vulnerability and usage, plus license and gitignore. The exploit is not framework-based. Core capability: authenticated RCE through OS command injection in OpenSTAManager's handling of uploaded .p7m invoice files. The vulnerable target code is documented as src/Util/XML.php::decodeP7M(), where an openssl command is built with an attacker-controlled filename inside double quotes; shell command substitution $(...) still executes. Because filenames cannot contain '/', the exploit base32-encodes the desired shell payload and constructs a malicious filename that decodes and pipes it to bash at execution time. Exploit flow: the script authenticates to the target using /index.php?op=login, verifies login by checking the root page for logout text, then submits a multipart POST to /actions.php with op=save and configurable id_module/id_plugin values (defaults 14/19) to reach the single-file importer path. The uploaded file content is benign placeholder data, while the filename carries the payload. The README notes the vulnerable path as POST /actions.php -> store(...) -> prepare -> FatturaElettronica::isValid(...) -> decodeP7M() -> exec(). Operational modes: (1) single-command blind execution, where stdout/stderr are redirected to /var/www/html/openstamanager/o.txt and then fetched via HTTP as /o.txt; (2) interactive pseudo-shell that repeatedly invokes blind commands and tracks cwd using pwd/cd logic; (3) reverse shell mode using bash over /dev/tcp to an operator-supplied listener host and port. Reverse shell delivery is expected to block the HTTP request, and the code intentionally ignores request exceptions in that case. Fingerprintable observables include the login endpoint, actions.php upload endpoint, retrieval of /o.txt, the default server-side webroot path /var/www/html/openstamanager, and the reverse-shell callback destination supplied by the operator. Overall, this is a real, functional authenticated RCE exploit with practical post-exploitation features rather than a mere detector or README-only PoC.
Single-file Python proof-of-concept exploit targeting OpenSTAManager RCE identified as CVE-2025-69212. The script uses the requests library to authenticate to the target web application with provided credentials, verifies success by checking for the PHPSESSID cookie, then builds an in-memory ZIP archive containing a maliciously named .p7m file. The filename embeds a bash command injection payload that launches a reverse shell to an attacker-supplied IP and port using /dev/tcp. After creating the archive, the exploit uploads it to the documents module via /index.php?module=documents&action=add with form fields name, description, id_anagrafica=1, and id_module=1. It then performs a GET request to /index.php?module=documents to trigger vulnerable processing. Repository structure is minimal: one executable Python file (poc.py) serving as both entry point and exploit logic. This is a real exploit rather than a detector, and its capability is authenticated remote code execution with a hardcoded bash reverse-shell payload.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-69212 affecting OpenSTAManager <= 2.9.8. The repository contains one primary exploit script (CVE-2025-69212.py), a README describing the vulnerability and usage, and an editor settings file. The exploit is not part of a larger framework. The exploit performs an authenticated attack against the web application. It first logs into OpenSTAManager at /index.php?op=login using provided credentials, then constructs an in-memory ZIP archive containing a malicious .p7m filename. The filename is crafted as invoice.p7m";<command>;echo ".p7m so that when the server processes the ZIP and passes the filename into an exec() call, arbitrary shell commands are injected. The script specifically builds a bash reverse shell payload, base64-encodes it to avoid slash characters in the ZIP entry name, and wraps it as echo <b64>|base64 -d|bash. After building the ZIP, the script uploads it to /actions.php with POST parameters op=save, id_module=14, and id_plugin=48, which correspond to the vulnerable import functionality described in the README. The upload is sent in a daemon thread because the reverse shell command may block and keep the HTTP request open. On success, the target initiates an outbound reverse shell connection to the attacker-specified LHOST:LPORT. Overall, the repository’s purpose is offensive exploitation of an authenticated OS command injection in OpenSTAManager’s ZIP import handling, resulting in remote code execution and an interactive shell. It is a real exploit with a working payload rather than a detector or scanner.
This repository is a small, standalone Python proof-of-concept exploit for CVE-2025-69212 affecting OpenSTAManager <= 2.9.8. The repo contains only two files: a Python exploit script and a README describing the vulnerability and usage. The exploit is not part of a larger framework. The main script, CVE-2025-69212.py, builds a malicious ZIP archive at /tmp/exploit.zip containing a crafted .p7m filename. The filename embeds a Python one-liner reverse shell payload inside shell metacharacters so that when the target application processes the ZIP and passes the filename into an exec()-backed openssl smime command, arbitrary OS commands execute. The script then sends the ZIP via an authenticated HTTP POST request to /plugins/importFE_ZIP/actions.php using a supplied PHPSESSID cookie and form fields op=save, id_module=14, and id_plugin=48. Primary capability: authenticated remote command execution leading to a reverse shell. The payload connects back to an attacker-specified host and port over TCP and spawns /bin/sh with I/O redirected to the socket. This makes the exploit operational rather than a simple detection script or documentation-only PoC. Repository structure is minimal and purpose-built: README.md explains the vulnerable code path and example usage, while CVE-2025-69212.py is the sole executable entry point. There is no scanning, brute forcing, persistence, or post-exploitation automation; the code focuses exclusively on delivering the malicious ZIP and triggering the command injection.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.