WebTareas SQL Injection Vulnerability in webTareasSID Cookie Parameter

Vulnerability

A SQL injection vulnerability has been identified in WebTareas version 2.4. The issue resides in the webTareasSID cookie parameter, allowing unauthenticated attackers to manipulate database queries. Exploitation of this vulnerability can lead to error-based and time-based blind SQL injection, enabling attackers to extract database information and potentially access sensitive system data.

Impact

Exploitation of this vulnerability allows for unauthorized SQL injection, which can be used to manipulate database queries, extract information from the database, and potentially access sensitive system data.

Reproduction

The vulnerability can be reproduced by sending a GET request to the webTareas administration page with a crafted webTareasSID cookie. The payload should include SQL injection techniques, such as error-based or time-based blind SQL injection, to exploit the vulnerability and extract database information.

Added: Dec 22, 2025, 10:45 PM
Updated: Dec 22, 2025, 10:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.0
remediation
0.0
relevance
1.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.