CVE-2026-107803

medium

Description

ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.

References

https://github.com/ProcessMaker/processmaker/security/advisories/GHSA-xf7p-gp7c-w7gh

https://github.com/ProcessMaker/processmaker/releases/tag/v2026.14.3

https://github.com/ProcessMaker/processmaker/pull/9041

https://github.com/ProcessMaker/processmaker/commit/2622b7ae810e02c47157028331c45470567e7b79

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95777

Details

Source: Mitre, NVD

Published: 2026-10-09

Updated: 2026-10-09

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium