rootpwn

medium · CVSS v3 6.3 · CVSS v4 5.3 · EPSS 0.00192

CVE-2026-100898

The CVE-2026-100898 vulnerability is a remote SQL injection in DevaslanPHP project-management’s Timesheet Dashboard component. It allows att

Overview

The CVE-2026-100898 vulnerability is a remote SQL injection in DevaslanPHP project-management’s Timesheet Dashboard component. It allows attackers to inject arbitrary SQL via the whereRaw function in ActivitiesReport.php, potentially exposing or altering sensitive data.

Description

A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

Confidentiality: attackers can read sensitive project and timesheet data. Integrity: attackers can modify or delete timesheet entries. Availability: large malicious queries could degrade database performance. Defenders: database administrators, application developers, and security teams are impacted.

Remediation

Apply the vendor patch or upgrade to a fixed version if available. If no patch, sanitize input by using parameterized queries or escaping values in the whereRaw function. Restrict remote access to the Timesheet Dashboard and monitor database logs for suspicious activity.

Risk context

Severity is medium (CVSS 6.3) with a low EPSS score of 0.00192, indicating a low probability of exploitation but still requiring timely mitigation to prevent data exposure.

Affected products

  • DevaslanPHP project-management 1.2.1
  • DevaslanPHP project-management 1.2.2
  • DevaslanPHP project-management 1.2.3
  • DevaslanPHP project-management 1.2.4
  • DevaslanPHP project-management 2.0.0-beta1

Scores

Severity
medium
CVSS v2
6.5
CVSS v3
6.3
CVSS v4
5.3
EPSS
0.00192

sql-injection remote database devaslanphp project-management medium-severity

← All CVEs