SQL Injection Flaw in DevaslanPHP Project Management Application
CVE-2026-100898
Key Information:
- Vendor
DevaslanPHP
- Status
- Vendor
- CVE Published:
- 28 September 2026
Badges
What is CVE-2026-100898?
A SQL injection vulnerability exists in the DevaslanPHP project management application's Timesheet Dashboard. Specifically, the issue is located in the app/Filament/Widgets/Timesheet/ActivitiesReport.php file within the whereRaw function. This vulnerability allows attackers to exploit improperly handled argument filters, leading to unauthorized access to the database. The potential for remote exploitation makes this issue particularly critical. Despite early notification to the vendor regarding the vulnerability, there has been no response, raising concerns about the security of affected software versions.
Affected Version(s)
project-management 1.2.1
project-management 1.2.2
project-management 1.2.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
