6.5
CVE-2026-107803
- EPSS -
- Veröffentlicht 09.10.2026 13:40:16
- Zuletzt bearbeitet 09.10.2026 17:08:31
- Erkennungen
ProcessMaker has SQL injection in the tasks endpoint through the order_by parameter
ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerProcessMaker
≫
Produkt
processmaker
Version
< 2026.14.3
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
https://github.com/ProcessMaker/processmaker/security/advisories/GHSA-xf7p-gp7c-w7gh
https://github.com/ProcessMaker/processmaker/pull/9041
https://github.com/ProcessMaker/processmaker/commit/2622b7ae810e02c47157028331c45470567e7b79
https://github.com/ProcessMaker/processmaker/releases/tag/v2026.14.3