ProcessMaker 是一款开源的工作流管理软件套件。在版本 2026.14.3 之前,ProcessMaker 的 接口存在 SQL 注入漏洞。该漏洞源于 方法中,将一个由用户可控的 表列名直接拼接到 构造的 SQL 子查询中,且未进行任何输入验证或使用参数化绑定。任何已认证用户均可利用基于时间的盲注技术,推断并提取 ProcessMaker 数据库账户可访问的数据。该问题已在版本 2026.14.3 中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ProcessMaker | processmaker | < 2026.14.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ProcessMaker | processmaker | < 2026.14.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet