Description
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

A flaw in the whereRaw function of DevaslanPHP project‑management’s ActivitiesReport widget allows attackers to inject arbitrary SQL statements. The vulnerability can be triggered remotely by manipulating the filter argument, potentially exposing or altering data in the underlying database. The vulnerability is classified under CWE‑74 (Improper Control of Generation of SQL Statements) and CWE‑89 (SQL Injection).

Affected Systems

DevaslanPHP project‑management versions 1.2.1, 1.2.2, 1.2.3, 1.2.4 and 2.0.0‑beta1 are affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote, meaning a legitimate user or attacker with access to the Application Layer can exploit it. The impact is potential data compromise, data loss, or modification of database contents.

Generated by OpenCVE AI on September 28, 2026 at 03:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest DevaslanPHP project‑management release that resolves the whereRaw SQL injection flaw. If no patch is available, plan to replace the vulnerable code with parameterized queries or the framework’s safe query builder.
  • Limit the database privileges of the application user to a minimum required set, removing direct table modification rights that could be abused via injection.
  • Implement input validation and sanitization on all filter parameters before they reach the database layer, ensuring that malicious payloads cannot be injected.

Generated by OpenCVE AI on September 28, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title DevaslanPHP project-management Timesheet Dashboard ActivitiesReport.php whereRaw sql injection
First Time appeared Devaslanphp
Devaslanphp project-management
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:*
Vendors & Products Devaslanphp
Devaslanphp project-management
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Devaslanphp Project-management
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T02:00:13.363Z

Reserved: 2026-09-27T08:47:32.353Z

Link: CVE-2026-100898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T02:17:19.973

Modified: 2026-09-28T02:17:19.973

Link: CVE-2026-100898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T03:30:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')