Vulnerabilities > Webtareas Project > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-12-02 CVE-2022-44290 SQL Injection vulnerability in Webtareas Project Webtareas 2.4
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
network
low complexity
webtareas-project CWE-89
critical
9.8
2022-12-02 CVE-2022-44291 SQL Injection vulnerability in Webtareas Project Webtareas 2.4
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
network
low complexity
webtareas-project CWE-89
critical
9.8
2022-04-20 CVE-2021-43481 SQL Injection vulnerability in Webtareas Project Webtareas
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
network
low complexity
webtareas-project CWE-89
critical
9.8