PT-2026-108909 · Processmaker · Processmaker
CVE-2026-107803
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the
GET /api/1.0/tasks endpoint in ProcessMaker is vulnerable to SQL injection through the order by parameter because ProcessMakerTraitsTaskControllerIndexMethods::applyColumnOrdering() concatenates a user-controlled process requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Processmaker