Unknown · Devaslanphp Project-Management · CVE-2026-100900
**Name of the Vulnerable Software and Affected Versions**
DevaslanPHP project-management versions 1.2.1 through 1.2.4
DevaslanPHP project-management version v2.0.0-beta1
**Description**
In the Jira Import component, the `updateJiraProjects()` function within the `/jira-import` file is susceptible to server-side request forgery (SSRF), a flaw that allows an attacker to induce the server-side application to make requests to an unintended location. This can be triggered remotely by manipulating the `host`, `username`, or `token` arguments.
**Recommendations**
As a temporary workaround, restrict access to the `/jira-import` file or disable the `updateJiraProjects()` function until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.