Skip to content
Noroxi

Qdpm records

18 published records for vendor qdpm.

All records

18 records
  • CVE-2020-7246
    60This week

    A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.

    HighCVSS 8.8WeaponizedEPSS 83%

    qdpm · qdpmJan 21, 2020

  • In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted conten

    CriticalCVSS 9.8No exploitEPSS 3%

    qdpm · qdpmApr 16, 2020

  • CVE-2015-3884
    39Monitor

    Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) sch

    HighCVSS 8.8WeaponizedEPSS 14%

    qdpm · qdpmMar 17, 2017

  • qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

    CriticalCVSS 9.8No exploitEPSS 1%

    qdpm · qdpmOct 14, 2023

  • qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.

    HighCVSS 8.8Proof of conceptEPSS 4%

    qdpm · qdpmApr 8, 2022

  • qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class

    HighCVSS 8.8No exploitEPSS 3%

    qdpm · qdpmDec 31, 2020

  • qdPM 9.1 SQL Injection via filter_by Parameters

    HighCVSS 8.8No exploitEPSS 0%

    qdpm · qdpmMar 26, 2026

  • qdPM 9.1 SQL Injection via search_by_extrafields Parameter

    HighCVSS 8.8No exploitEPSS 0%

    qdpm · qdpmApr 5, 2026

  • qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.

    HighCVSS 7.5Proof of conceptEPSS 3%

    qdpm · qdpmOct 14, 2023

  • CVE-2015-3881
    30Monitor

    Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/dat

    HighCVSS 7.5No exploitEPSS 2%

    qdpm · qdpmMar 17, 2017

  • CVE-2019-8390
    27Monitor

    qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

    MediumCVSS 6.1Proof of conceptEPSS 10%

    qdpm · qdpmMay 14, 2019

  • CVE-2019-8391
    25Monitor

    qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.

    MediumCVSS 6.1Proof of conceptEPSS 3%

    qdpm · qdpmMay 14, 2019

  • qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.

    MediumCVSS 6.1Proof of conceptEPSS 2%

    qdpm · qdpmSep 9, 2021

  • CVE-2015-3883
    24Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) se

    MediumCVSS 6.1No exploitEPSS 1%

    qdpm · qdpmMar 17, 2017

  • CVE-2015-3882
    21Monitor

    qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the ins

    MediumCVSS 5.3No exploitEPSS 1%

    qdpm · qdpmMar 17, 2017

  • A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious website

    MediumCVSS 5.4No exploitEPSS 1%

    qdpm · qdpmApr 16, 2020

  • The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web scri

    MediumCVSS 5.4No exploitEPSS 1%

    qdpm · qdpmOct 5, 2020

  • Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a c

    MediumCVSS 5.4No exploitEPSS 0%

    qdpm · qdpmAug 26, 2021