CVE-2022-44291
WebTareas 2.4p5 - SQL Injection
Record summary
CVE-2022-44291 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 24, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALWebTareas 2.4p5 - SQL InjectionCVSS 9.8
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
Impact
Authenticated attackers can execute time-based blind SQL injection through the id parameter in phasesets.php, potentially extracting sensitive database information including project phases, task data, and user credentials from WebTareas.
Remediation
Update WebTareas to a version later than 2.4p5 that properly sanitizes and parameterizes the id parameter in phasesets.php.
Source: ProjectDiscovery