VYPR
Medium severity6.5NVD Advisory· Published Oct 9, 2026

CVE-2026-107803

CVE-2026-107803

Description

ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the GET /api/1.0/tasks endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering() concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.