Unauthenticated SQL Injection in ProjeQtor by ProjeQtor

⚠️ CVE-Referenzen: CVE-2026-41462
Projeqtor - Projeqtor - CRITICAL - CVE-2026-41462. ProjeQtor versions 7.0 to 12.4.3 are susceptible to an unauthenticated SQL injection vulnerability within the login functionality. This occurs when the application dynamically constructs SQL queries without proper parameterization or sanitization of user inputs. Attackers can exploit this vulnerability by injecting arbitrary SQL commands through the login field, potentially allowing them to create unauthorized privileged accounts, access sensitive information, and execute system-level commands if the database user possesses elevated privileges.
Quelle: securityvulnerability.io