No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 29 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projeqtor
Projeqtor projeqtor |
|
| Vendors & Products |
Projeqtor
Projeqtor projeqtor |
Mon, 27 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the authentication endpoint to create privileged accounts, read sensitive data, and execute operating system commands if the database user has elevated permissions. | |
| Title | ProjeQtor < 12.4.4 Unauthenticated SQL Injection via Login | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-27T17:43:49.325Z
Reserved: 2026-04-20T16:07:47.310Z
Link: CVE-2026-41462
Updated: 2026-04-27T17:43:43.654Z
Status : Deferred
Published: 2026-04-27T16:16:45.340
Modified: 2026-04-27T18:36:19.637
Link: CVE-2026-41462
No data.
OpenCVE Enrichment
Updated: 2026-04-28T04:30:21Z