CVE-2026-100898
Received Received - Intake

SQL Injection in DevaslanPHP Project-Management

Vulnerability report for CVE-2026-100898, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
devaslanphp project-management to 1.2.4 (inc)
devaslanphp project-management 2.0.0-beta1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-100898 is a SQL injection vulnerability in the DevaslanPHP project-management system affecting versions up to 1.2.4 and v2.0.0-beta1. The issue is in the Timesheet Dashboard's ActivitiesReport component where user input in the $filter parameter is directly used in a raw SQL query without validation. Attackers can manipulate this to inject malicious SQL code.

Detection Guidance

To detect this SQL injection vulnerability, inspect network traffic for Livewire update requests targeting the TimesheetDashboard component. Look for POST requests to /livewire/update with a payload containing the filter parameter modified with SQL injection payloads like updatexml or subqueries. Check server logs for unusual SQL errors or queries with injected strings.

Impact Analysis

This vulnerability allows attackers to execute arbitrary SQL commands on the database. This could lead to unauthorized data access, data modification if write permissions exist, or database downtime through resource-intensive queries. The attack only requires a valid authenticated session.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, which directly violates GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations using this software may face compliance violations and potential legal consequences.

Mitigation Strategies

Immediately update DevaslanPHP project-management to the latest patched version if available. If no patch exists, disable the Timesheet Dashboard feature or restrict access to authenticated users with strict role-based permissions. Implement input validation and use parameterized queries instead of whereRaw with user-controlled input.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100898. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart