ProjeQtor Missing Authorization Vulnerability in objectDetail.php Endpoint

Vulnerability

A missing authorization vulnerability has been identified in ProjeQtor versions 7.0 prior to 12.4.4. This vulnerability exists in the objectDetail.php endpoint, where authenticated users with guest-level privileges can access sensitive data belonging to other users, such as password hashes and API keys. The lack of proper authorization checks allows these users to bypass access controls and directly retrieve information that could include administrator credentials, potentially leading to privilege escalation.

Impact

Exploitation of this vulnerability could allow low-privileged users to access and extract sensitive information from other users, including password hashes and API keys. Such data could be used to gain unauthorized access to accounts or escalate privileges within the application.

Remediation

It is recommended that ProjeQtor implement server-side authorization checks for all endpoints that return object details. The application should ensure that users have the appropriate permissions to access requested data, regardless of the frontend controls. This vulnerability can be addressed by updating to ProjeQtor version 12.4.4 or later, where this authorization issue has been fixed.

Added: Apr 27, 2026, 4:29 PM
Updated: Apr 27, 2026, 4:29 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
6.6
remediation
0.0
relevance
6.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.