CVE-2026-100900 | DevaslanPHP project-management up to v2.0.0-beta1 Jira Import /jira-import updateJiraProjects host/username/token server-side request forgery

SecurityVulns

A vulnerability was found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. It has been classified as problematic. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery.

This vulnerability is traded as CVE-2026-100900. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More