CVE-2025-14580
- EPSS 0.21%
- Veröffentlicht 12.12.2025 20:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in Qualitor up to 8.24.73. The impacted element is an unknown function of the file /Qualitor/html/bc/bcdocumento9/biblioteca/request/viewDocumento.php. Such manipulation of the argument cdscript leads to cro...
CVE-2025-13792
- EPSS 0.4%
- Veröffentlicht 30.11.2025 16:02:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros results in co...
CVE-2025-5139
- EPSS 2.95%
- Veröffentlicht 25.05.2025 01:15:23
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /html/ad/adconexaooffice365/request/testaConexaoOffice365.php of the component Office 365-type Connection...
CVE-2024-48359
- EPSS 2.22%
- Veröffentlicht 31.10.2024 20:15:05
- Zuletzt bearbeitet 01.07.2025 20:36:59
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.
CVE-2024-48360
- EPSS 3.91%
- Veröffentlicht 31.10.2024 20:15:05
- Zuletzt bearbeitet 01.07.2025 20:36:49
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.
CVE-2024-44849
- EPSS 46.3%
- Veröffentlicht 09.09.2024 18:15:03
- Zuletzt bearbeitet 01.07.2025 20:37:06
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
CVE-2023-47253
- EPSS 14.42%
- Veröffentlicht 06.11.2023 06:15:40
- Zuletzt bearbeitet 07.07.2025 18:50:25
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.