Description
A flaw has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: SQL injection via the whereRaw function allows remote attackers to manipulate the filter argument to execute arbitrary SQL statements, potentially exposing or modifying sensitive data.
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the whereRaw function within the Timesheet Dashboard’s MonthlyReport component of DevaslanPHP project-management. By manipulating the filter argument, an attacker can inject malicious SQL, enabling unauthorized data exfiltration or alteration. This flaw permits remote exploitation, with published exploits already available. The impact is primarily the compromise of data confidentiality and integrity, and it can affect all users of the affected system.

Affected Systems

DevaslanPHP project-management is vulnerable in versions 1.2.1, 1.2.2, 1.2.3, 1.2.4, and the beta release v2.0.0‑beta1. No specific subcomponent or operating system is mentioned beyond the Timesheet Dashboard widget that houses the vulnerable code. Users should verify that they are running one of these versions and isolate or upgrade accordingly.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The known exploit code suggests that the flaw is actively exploited in the wild. Although the absence of EPSS data limits precise likelihood estimation, the published nature of the exploit implies a non-negligible risk, particularly for publicly exposed instances of the application. The attack can be carried out remotely by sending crafted requests to the whereRaw endpoint, implying that the vulnerability is potentially exploitable without local access.

Generated by OpenCVE AI on September 28, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version of DevaslanPHP project-management that fixes the whereRaw SQL injection flaw; if an official patch is not available, obtain the source and manually review the whereRaw implementation for missing parameterization.
  • If upgrading is not immediately possible, apply a workaround by sanitizing or validating input to the filter argument before it is passed to whereRaw, ensuring that only safe SQL fragments are allowed.
  • Configure a web application firewall or database access controls to block or monitor attempts to execute arbitrary SQL, reducing the window of opportunity for an attacker to exploit the vulnerability.

Generated by OpenCVE AI on September 28, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title DevaslanPHP project-management Timesheet Dashboard MonthlyReport.php whereRaw sql injection
First Time appeared Devaslanphp
Devaslanphp project-management
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:*
Vendors & Products Devaslanphp
Devaslanphp project-management
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Devaslanphp Project-management
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T02:15:16.991Z

Reserved: 2026-09-27T08:47:36.176Z

Link: CVE-2026-100899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T03:16:38.447

Modified: 2026-09-28T03:16:38.447

Link: CVE-2026-100899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T05:30:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')