Impact
A flaw in the whereRaw function of DevaslanPHP project‑management’s ActivitiesReport widget allows attackers to inject arbitrary SQL statements. The vulnerability can be triggered remotely by manipulating the filter argument, potentially exposing or altering data in the underlying database. The vulnerability is classified under CWE‑74 (Improper Control of Generation of SQL Statements) and CWE‑89 (SQL Injection).
Affected Systems
DevaslanPHP project‑management versions 1.2.1, 1.2.2, 1.2.3, 1.2.4 and 2.0.0‑beta1 are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote, meaning a legitimate user or attacker with access to the Application Layer can exploit it. The impact is potential data compromise, data loss, or modification of database contents.
OpenCVE Enrichment