CVE-2026-100898 | DevaslanPHP project-management up to 2.0.0-beta1 Timesheet Dashboard ActivitiesReport.php whereRaw filter sql injection

SecurityVulns

A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1 and classified as critical. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection.

This vulnerability is reported as CVE-2026-100898. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More