PT-2022-27169 · Webtareas · Webtareas

Anhdq201

·

Published

2022-12-02

·

Updated

2022-12-06

·

CVE-2022-44290

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions webTareas version 2.4p5
Description A SQL injection issue was found in webTareas via the id parameter in the "deleteapprovalstages.php" endpoint. This allows for potential exploitation.
Recommendations For webTareas version 2.4p5, avoid using the id parameter in the "deleteapprovalstages.php" endpoint until a fix is available. Consider restricting access to this endpoint as a temporary mitigation measure. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-44290

Affected Products

Webtareas