在 DevaslanPHP 项目管理系统 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1 版本中发现了一个漏洞。该漏洞影响 Timesheet Dashboard(时间簿仪表板)组件中文件 app/Filament/Widgets/Timesheet/ActivitiesReport.php 的 whereRaw 函数。通过操纵 filter 参数,可导致 SQL 注入。该漏洞可被远程利用。目前相关利用代码已公开,可被用于实施攻击。开发人员在披露初期已被联系,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| DevaslanPHP | project-management | 1.2.1 |
cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100899 | 6.3 MEDIUM | DevaslanPHP project-management Timesheet Dashboard MonthlyReport.php whereRaw sql injectio |
| CVE-2026-100900 | 5.5 MEDIUM | DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side requ |
No comments yet