Impact
The vulnerability resides in the whereRaw function within the Timesheet Dashboard’s MonthlyReport component of DevaslanPHP project-management. By manipulating the filter argument, an attacker can inject malicious SQL, enabling unauthorized data exfiltration or alteration. This flaw permits remote exploitation, with published exploits already available. The impact is primarily the compromise of data confidentiality and integrity, and it can affect all users of the affected system.
Affected Systems
DevaslanPHP project-management is vulnerable in versions 1.2.1, 1.2.2, 1.2.3, 1.2.4, and the beta release v2.0.0‑beta1. No specific subcomponent or operating system is mentioned beyond the Timesheet Dashboard widget that houses the vulnerable code. Users should verify that they are running one of these versions and isolate or upgrade accordingly.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The known exploit code suggests that the flaw is actively exploited in the wild. Although the absence of EPSS data limits precise likelihood estimation, the published nature of the exploit implies a non-negligible risk, particularly for publicly exposed instances of the application. The attack can be carried out remotely by sending crafted requests to the whereRaw endpoint, implying that the vulnerability is potentially exploitable without local access.
OpenCVE Enrichment