Vulnerability record · CVE-2019-11600 · published 13 May 2019
CVE-2019-11600: OpenProject activities API SQL injection via id parameter
Openproject · Openproject
OpenProject before 8.3.2 contains a SQL injection flaw in the activities API, reachable through the id parameter. An attacker can inject arbitrary SQL commands, and the attack can be performed unauthenticated when the instance is configured to allow API access without authentication. This matters because it exposes the backend database to direct manipulation or extraction.
Description
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote SQL injection with a high CVSS score, public exploit references and very high EPSS, though exploitation requires the instance to permit unauthenticated API access.
What it is
OpenProject before 8.3.2 contains a SQL injection flaw in the activities API, reachable through the id parameter. An attacker can inject arbitrary SQL commands, and the attack can be performed unauthenticated when the instance is configured to allow API access without authentication. This matters because it exposes the backend database to direct manipulation or extraction.
Impact
An attacker gains the ability to execute arbitrary SQL against the OpenProject database, enabling data theft, modification or deletion, and potentially further compromise depending on database privileges.
Attack surface
Reached remotely over the network through the activities API endpoint using the id parameter. No user interaction is required; authentication is not needed if the instance is configured for unauthenticated API access, though the CVSS vector rates attack complexity as high.
Exploitation
Not listed in CISA KEV, but EPSS is very high at roughly 0.80 (99.6th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade OpenProject to 8.3.2 or later, which is the vendor-fixed release.
- If immediate upgrade is not possible, require authentication for all API access and restrict the activities API to trusted networks.
- Apply input validation or a WAF rule blocking SQL metacharacters in the id parameter of the activities API.
- Review database account privileges used by OpenProject and reduce them to the minimum needed.
- Audit logs for prior suspicious requests to the activities API endpoint.
Detection
- Monitor web and API logs for requests to the activities endpoint with SQL syntax or unexpected characters in the id parameter.
- Alert on database errors or unusual query patterns originating from the OpenProject application account.
- Hunt for anomalous data access or bulk reads from OpenProject-related database tables.
- Correlate outbound or lateral activity from the OpenProject host following suspicious API requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/152806/OpenProject-8.3.1-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/May/7 | ExploitMailing ListThird Party Advisory |
| https://groups.google.com/forum/#%21msg/openproject-security/XlucAJMxmzM/hESpOaFVAwAJ | |
| https://seclists.org/bugtraq/2019/May/22 | ExploitIssue TrackingMailing ListThird Party Advisory |
| https://www.openproject.org/release-notes/openproject-8-3-2/ | Vendor Advisory |
| http://packetstormsecurity.com/files/152806/OpenProject-8.3.1-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/May/7 | ExploitMailing ListThird Party Advisory |
| https://groups.google.com/forum/#%21msg/openproject-security/XlucAJMxmzM/hESpOaFVAwAJ | |
| https://seclists.org/bugtraq/2019/May/22 | ExploitIssue TrackingMailing ListThird Party Advisory |
| https://www.openproject.org/release-notes/openproject-8-3-2/ | Vendor Advisory |
Track CVE-2019-11600 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11600), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.