ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the authentication endpoint to create privileged accounts, read sensitive data, and execute operating system commands if the database user has elevated permissions.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projeqtor
Projeqtor projeqtor |
|
| Vendors & Products |
Projeqtor
Projeqtor projeqtor |
Mon, 27 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the authentication endpoint to create privileged accounts, read sensitive data, and execute operating system commands if the database user has elevated permissions. | |
| Title | ProjeQtor < 12.4.4 Unauthenticated SQL Injection via Login | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-27T15:08:35.678Z
Updated: 2026-04-27T17:43:49.325Z
Reserved: 2026-04-20T16:07:47.310Z
Link: CVE-2026-41462
Updated: 2026-04-27T17:43:43.654Z
Status : Deferred
Published: 2026-04-27T16:16:45.340
Modified: 2026-04-27T18:36:19.637
Link: CVE-2026-41462
No data.
ReportizFlow