CVE-2026-100899 | DevaslanPHP project-management up to v2.0.0-beta1 Timesheet Dashboard MonthlyReport.php whereRaw filter sql injection

SecurityVulns

A vulnerability was found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1 and classified as critical. This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. Executing a manipulation of the argument filter can lead to sql injection.

This vulnerability appears as CVE-2026-100899. The attack may be performed from remote. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More