← Vulnerability feed

Vulnerability record · CVE-2019-11600 · published 13 May 2019

CVE-2019-11600: OpenProject activities API SQL injection via id parameter

Openproject · Openproject

OpenProject before 8.3.2 contains a SQL injection flaw in the activities API, reachable through the id parameter. An attacker can inject arbitrary SQL commands, and the attack can be performed unauthenticated when the instance is configured to allow API access without authentication. This matters because it exposes the backend database to direct manipulation or extraction.

8.1 CVSS 3.0 High EPSS 80% · top 0.4% CWE-89 · SQL injection
8.1CVSS 3.0 base score, v2 6.8
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote SQL injection with a high CVSS score, public exploit references and very high EPSS, though exploitation requires the instance to permit unauthenticated API access.

What it is

OpenProject before 8.3.2 contains a SQL injection flaw in the activities API, reachable through the id parameter. An attacker can inject arbitrary SQL commands, and the attack can be performed unauthenticated when the instance is configured to allow API access without authentication. This matters because it exposes the backend database to direct manipulation or extraction.

Impact

An attacker gains the ability to execute arbitrary SQL against the OpenProject database, enabling data theft, modification or deletion, and potentially further compromise depending on database privileges.

Attack surface

Reached remotely over the network through the activities API endpoint using the id parameter. No user interaction is required; authentication is not needed if the instance is configured for unauthenticated API access, though the CVSS vector rates attack complexity as high.

Exploitation

Not listed in CISA KEV, but EPSS is very high at roughly 0.80 (99.6th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade OpenProject to 8.3.2 or later, which is the vendor-fixed release.
  • If immediate upgrade is not possible, require authentication for all API access and restrict the activities API to trusted networks.
  • Apply input validation or a WAF rule blocking SQL metacharacters in the id parameter of the activities API.
  • Review database account privileges used by OpenProject and reduce them to the minimum needed.
  • Audit logs for prior suspicious requests to the activities API endpoint.

Detection

  • Monitor web and API logs for requests to the activities endpoint with SQL syntax or unexpected characters in the id parameter.
  • Alert on database errors or unusual query patterns originating from the OpenProject application account.
  • Hunt for anomalous data access or bulk reads from OpenProject-related database tables.
  • Correlate outbound or lateral activity from the OpenProject host following suspicious API requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11600 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-25763Openproject os command injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exis…EPSS 0.68%9.4CVE-2026-24685Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability …EPSS 0.36%9.1CVE-2026-22600Openproject information exposure vulnerabilityOpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun…EPSS 0.31%9.0CVE-2026-24772Openproject insufficient verification of data authenticity vulnerabilityOpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced…EPSS 0.19%8.8CVE-2021-43830Openproject sql injection vulnerabilityOpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For a…EPSS 0.93%8.6CVE-2026-22601Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut…EPSS 0.37%8.1CVE-2026-34717Openproject sql injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operat…EPSS 0.45%8.1CVE-2017-11667Openproject insufficient session expiration vulnerabilityOpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leve…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2019-11600), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.