medium · CVSS v3 6.3 · CVSS v4 5.3 · EPSS 0.00192
CVE-2026-100898
The CVE-2026-100898 vulnerability is a remote SQL injection in DevaslanPHP project-management’s Timesheet Dashboard component. It allows att
Overview
The CVE-2026-100898 vulnerability is a remote SQL injection in DevaslanPHP project-management’s Timesheet Dashboard component. It allows attackers to inject arbitrary SQL via the whereRaw function in ActivitiesReport.php, potentially exposing or altering sensitive data.
Description
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Confidentiality: attackers can read sensitive project and timesheet data. Integrity: attackers can modify or delete timesheet entries. Availability: large malicious queries could degrade database performance. Defenders: database administrators, application developers, and security teams are impacted.
Remediation
Apply the vendor patch or upgrade to a fixed version if available. If no patch, sanitize input by using parameterized queries or escaping values in the whereRaw function. Restrict remote access to the Timesheet Dashboard and monitor database logs for suspicious activity.
Risk context
Severity is medium (CVSS 6.3) with a low EPSS score of 0.00192, indicating a low probability of exploitation but still requiring timely mitigation to prevent data exposure.
Affected products
- DevaslanPHP project-management 1.2.1
- DevaslanPHP project-management 1.2.2
- DevaslanPHP project-management 1.2.3
- DevaslanPHP project-management 1.2.4
- DevaslanPHP project-management 2.0.0-beta1
Scores
- Severity
- medium
- CVSS v2
- 6.5
- CVSS v3
- 6.3
- CVSS v4
- 5.3
- EPSS
- 0.00192