SunshineOtaku/Report-CVE

SunshineOtaku/Report-CVE

Releases0
Used to report vulnerabilities to the CVE official

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.

9.8 CRITICAL

qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.