PT-2026-85221 · Worklenz · Worklenz
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Worklenz versions prior to 3.0.1
Description
Authenticated users can inject arbitrary PostgreSQL expressions into ORDER BY clauses because pagination helper functions do not properly validate the
sort-field query parameter. This allows the use of time-based and boolean-based blind SQL injection—techniques used to infer data by observing server response times or true/false responses—to extract sensitive database content, such as password hashes from other tenants.Recommendations
Update Worklenz to a version newer than 3.0.0.
Avoid using the
sort-field parameter in pagination requests until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Worklenz