Back

HIGH

infinitietech taskhub GET Parameter get_tasks_list sql injection

Published Sep 15, 2023

Description

A vulnerability, which was classified as critical, has been found in infinitietech taskhub 2.8.7. Affected by this issue is some unknown functionality of the file /home/get_tasks_list of the component GET Parameter Handler. The manipulation of the argument project/status/user_id/sort/search leads to sql injection. VDB-239798 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published Sep 15, 2023
Updated Sep 25, 2024
Reserved Sep 15, 2023

CISA Vulnrichment

Updated Sep 25, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulDB
Published Sep 15, 2023
Updated Sep 25, 2024

GitHub

No data