Sceawere
Vulnerability Detail
CVE-2026-100899UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in DevaslanPHP Timesheet
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 5h ago
- Vendor
- DevaslanPHP
- Product
- project-management
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-28T03:16:38.447Z",
"pubdate": "2026-09-28T03:16:38.447Z",
"executiveSummary": "A SQL Injection vulnerability exists in the Timesheet Dashboard component of the DevaslanPHP project-management application.\nThe vulnerability originates from the improper handling of user-supplied input within the whereRaw function in app/Filament/Widgets/Timesheet/MonthlyReport.php.\nSuccessful exploitation allows a remote, unauthenticated attacker to inject malicious SQL commands into the backend database queries.\nThis flaw compromises the confidentiality, integrity, and availability of the application data, potentially leading to unauthorized data exfiltration, modification, or complete database takeover.\nThe vulnerability affects versions 1.2.1, 1.2.2, 1.2.3, 1.2.4, and v2.0.0-beta1.\nGiven that public exploit code is available and the vendor has remained unresponsive to disclosure, this represents a high-risk security posture for organizations utilizing the affected versions.",
"technicalDetails": "The vulnerability resides in the MonthlyReport widget of the Timesheet Dashboard component, specifically within the app/Filament/Widgets/Timesheet/MonthlyReport.php file. The root cause is the insecure utilization of the Eloquent whereRaw() method, which fails to properly sanitize the input provided via the 'filter' argument before incorporating it into a database query string.\nIn Laravel-based applications, the whereRaw() method is intended for raw SQL expressions and is inherently dangerous if user-controlled input is concatenated directly into the query string without parameterized bindings. In this instance, the 'filter' parameter is processed by the widget's logic and passed directly into the SQL command context.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP request to the target application containing a malicious payload in the 'filter' argument. Because the application logic does not employ parameter binding or input validation, the malicious input breaks out of the intended query structure. This allows the attacker to terminate the original query and append arbitrary SQL commands using operations like UNION SELECT, boolean-based inference, or time-based blind SQL injection techniques.\nBy manipulating the 'filter' argument, an attacker can bypass existing authentication or authorization mechanisms to access sensitive project data, user credentials, or system configuration stored within the database. Furthermore, depending on the database configuration and permissions of the application's database user, an attacker may be able to read files from the filesystem, write files to the server, or execute administrative commands.\nThe vulnerability is remotely exploitable and does not require prior authentication, significantly increasing the potential attack surface. Since the exploit is publicly documented, malicious actors can easily automate the discovery and exploitation process against exposed instances of the DevaslanPHP project-management software.\nPost-exploitation impact includes full database compromise, unauthorized modification of project metrics, exfiltration of proprietary project data, and potential lateral movement into the underlying infrastructure if the database service is improperly configured or shares credentials with other internal services."
}