İçeriğe atla
Noroxi

Qdpm kayıtları

qdpm üreticisine ait 18 yayımlanmış kayıt.

Tüm kayıtlar

18 kayıt
  • CVE-2020-7246
    60Bu hafta

    A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %83

    qdpm · qdpm21 Oca 2020

  • CVE-2020-11811
    40Planlayın

    In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted conten

    KritikCVSS 9,8İstismar yokEPSS %3

    qdpm · qdpm16 Nis 2020

  • CVE-2015-3884
    39İzleyin

    Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) sch

    YüksekCVSS 8,8SilahlaştırılmışEPSS %14

    qdpm · qdpm17 Mar 2017

  • CVE-2023-45856
    39İzleyin

    qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

    KritikCVSS 9,8İstismar yokEPSS %1

    qdpm · qdpm14 Eki 2023

  • CVE-2022-26180
    36İzleyin

    qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    qdpm · qdpm8 Nis 2022

  • CVE-2020-26165
    36İzleyin

    qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class

    YüksekCVSS 8,8İstismar yokEPSS %3

    qdpm · qdpm31 Ara 2020

  • CVE-2018-25208
    35İzleyin

    qdPM 9.1 SQL Injection via filter_by Parameters

    YüksekCVSS 8,8İstismar yokEPSS %0

    qdpm · qdpm26 Mar 2026

  • CVE-2019-25669
    35İzleyin

    qdPM 9.1 SQL Injection via search_by_extrafields Parameter

    YüksekCVSS 8,8İstismar yokEPSS %0

    qdpm · qdpm5 Nis 2026

  • CVE-2023-45855
    31İzleyin

    qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    qdpm · qdpm14 Eki 2023

  • CVE-2015-3881
    30İzleyin

    Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/dat

    YüksekCVSS 7,5İstismar yokEPSS %2

    qdpm · qdpm17 Mar 2017

  • CVE-2019-8390
    27İzleyin

    qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

    OrtaCVSS 6,1Kavram kanıtıEPSS %10

    qdpm · qdpm14 May 2019

  • CVE-2019-8391
    25İzleyin

    qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    qdpm · qdpm14 May 2019

  • CVE-2020-19515
    25İzleyin

    qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    qdpm · qdpm9 Eyl 2021

  • CVE-2015-3883
    24İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) se

    OrtaCVSS 6,1İstismar yokEPSS %1

    qdpm · qdpm17 Mar 2017

  • CVE-2015-3882
    21İzleyin

    qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the ins

    OrtaCVSS 5,3İstismar yokEPSS %1

    qdpm · qdpm17 Mar 2017

  • CVE-2020-11814
    21İzleyin

    A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious website

    OrtaCVSS 5,4İstismar yokEPSS %1

    qdpm · qdpm16 Nis 2020

  • CVE-2020-26166
    21İzleyin

    The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web scri

    OrtaCVSS 5,4İstismar yokEPSS %1

    qdpm · qdpm5 Eki 2020

  • CVE-2020-18468
    21İzleyin

    Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a c

    OrtaCVSS 5,4İstismar yokEPSS %0

    qdpm · qdpm26 Ağu 2021