vendor:
OpenProject
by:
T. Soo (Office Bangkok)
8.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: OpenProject
Affected Version From: 5.0.0
Affected Version To: 8.3.1
Patch Exists: YES
Related CWE: CVE-2019-11600
CPE: a:openproject:openproject
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Unauthenticated SQL Injection vulnerability
An SQL injection vulnerability has been identified in the web "activities API". An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if OpenProject is configured not to require authentication for API access.
Mitigation:
Upgrade to version 8.3.2 or 9.0.0