Sceawere
Vulnerability Detail
CVE-2026-100898UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DevaslanPHP SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 6h ago
- Vendor
- DevaslanPHP
- Product
- project-management
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-28T02:17:19.973Z",
"pubdate": "2026-09-28T02:17:19.973Z",
"executiveSummary": "A critical SQL injection vulnerability exists in the DevaslanPHP project-management application, specifically within the Timesheet Dashboard component.\nThe vulnerability arises from the improper sanitization of user-supplied input passed to the whereRaw function within the ActivitiesReport.php file.\nSuccessful exploitation allows a remote, unauthenticated, or authenticated attacker to inject arbitrary SQL commands into the application's database queries.\nThe impact includes unauthorized data exfiltration, modification of database contents, potential bypass of authentication mechanisms, and administrative control over the underlying database server.\nAffected versions include DevaslanPHP project-management 1.2.1, 1.2.2, 1.2.3, 1.2.4, and 2.0.0-beta1.\nThe vulnerability is currently subject to public exploits, and given the vendor's lack of responsiveness, it poses a high risk to organizations deploying this software.",
"technicalDetails": "The vulnerability is located in the app/Filament/Widgets/Timesheet/ActivitiesReport.php file of the DevaslanPHP project-management application. The root cause is the unsafe usage of the 'whereRaw' method, which is intended for executing raw SQL fragments within Laravel's Eloquent ORM or Query Builder context.\nIn this specific implementation, the 'filter' argument provided by the user is concatenated directly into the SQL query string passed to whereRaw without sufficient input validation or parameterization. Because the whereRaw method does not automatically sanitize input as prepared statements do, it creates a direct vector for SQL injection.\nThe attack flow begins when an attacker identifies the Timesheet Dashboard component and intercepts the request carrying the 'filter' parameter. By manipulating this argument, the attacker can break out of the intended query context by injecting SQL syntax characters such as single quotes, semicolons, or comments (e.g., --, #).\nFor example, an attacker may append UNION SELECT statements to retrieve sensitive data from other tables, or utilize boolean-based or time-based blind SQL injection techniques to enumerate the database structure, table names, and user credentials. The attack is executable remotely over HTTP/HTTPS, requiring no specific administrative privileges if the endpoint is exposed to the public internet.\nThe exploit payload is processed by the underlying database engine (e.g., MySQL or MariaDB) as part of the primary query. Since the application fails to utilize parameter binding (e.g., using placeholders like '?' or named parameters), the database engine is unable to distinguish between legitimate query logic and the attacker-supplied malicious code. Post-exploitation impact varies depending on the database user permissions; however, in many deployments, this leads to full read/write access to the application's data layer, significantly compromising the integrity, confidentiality, and availability of the project-management platform."
}