CVE-2026-100898: DevaslanPHP project-management Timesheet Dashboard ActivitiesReport.php whereRaw sql injection
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an authenticated account?
Yes. The CVSS vector lists PR:L, indicating an attacker needs low-level privileges, but no user interaction is required. The attack can be performed remotely.
Which releases should be treated as affected?
The reported affected releases are 1.2.1, 1.2.2, 1.2.3, 1.2.4, and 2.0.0-beta1.
How urgent is remediation?
A public exploit is available and may be used. The issue can affect confidentiality, integrity, and availability at low impact according to the supplied CVSS vector.