← Vulnerability feed

Vulnerability record · CVE-2021-43830 · published 14 December 2021

CVE-2021-43830: Openproject sql injection vulnerability

Openproject · Openproject

OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to reassign work packages to another budget unsufficiently sanitizes user input in the `reassign_to_id` parameter. The vulnerability has been fixed in version 12.0.4. Versions prior to 12.0.0 are not affected. If you're upgrading from an older version, ensure you are upgrading to at least version 12.0.4. If you are unable to upgrade in a timely fashion, the following patch can be applied: https://github.com/opf/openproject/pull/9983.patch

8.8 CVSS 3.1 High EPSS 0.93% · top 41.0% CWE-89 · SQL injection
8.8CVSS 3.1 base score, v2 6.5
0.93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to reassign work packages to another budget unsufficiently sanitizes user input in the `reassign_to_id` parameter. The vulnerability has been fixed in version 12.0.4. Versions prior to 12.0.0 are not affected. If you're upgrading from an older version, ensure you are upgrading to at least version 12.0.4. If you are unable to upgrade in a timely fashion, the following patch can be applied: https://github.com/opf/openproject/pull/9983.patch

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43830 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-25763Openproject os command injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exis…EPSS 0.68%9.4CVE-2026-24685Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability …EPSS 0.36%9.1CVE-2026-22600Openproject information exposure vulnerabilityOpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun…EPSS 0.31%9.0CVE-2026-24772Openproject insufficient verification of data authenticity vulnerabilityOpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced…EPSS 0.19%8.6CVE-2026-22601Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut…EPSS 0.37%8.1CVE-2026-34717Openproject sql injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operat…EPSS 0.45%8.1CVE-2019-11600OpenProject activities API SQL injection via id parameterOpenProject before 8.3.2 contains a SQL injection flaw in the activities API, reachable through the id parameter. An attacker can inject arbitrary SQ…EPSS 80%analysed8.1CVE-2017-11667Openproject insufficient session expiration vulnerabilityOpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leve…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-43830), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.