ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the authentication endpoint to create privileged accounts, read sensitive data, and execute operating system commands if the database user has elevated permissions.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the authentication endpoint to create privileged accounts, read sensitive data, and execute operating system commands if the database user has elevated permissions. | |
| Title | ProjeQtor < 12.4.4 Unauthenticated SQL Injection via Login | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-27T15:08:35.678Z
Reserved: 2026-04-20T16:07:47.310Z
Link: CVE-2026-41462
No data.
Status : Received
Published: 2026-04-27T16:16:45.340
Modified: 2026-04-27T16:16:45.340
Link: CVE-2026-41462
No data.
OpenCVE Enrichment
No data.