PT-2023-31400 · Infinitietech · Infinitietech Taskhub

Skalvin

·

Published

2023-09-15

·

Updated

2024-05-17

·

CVE-2023-4987

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions infinitietech taskhub version 2.8.7
Description A critical issue has been found in the GET Parameter Handler component, specifically affecting the /home/get tasks list file. The manipulation of the project/status/user id/sort/search argument leads to SQL injection.
Recommendations For infinitietech taskhub version 2.8.7, consider restricting access to the project/status/user id/sort/search argument in the GET Parameter Handler component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-4987

Affected Products

Infinitietech Taskhub