Qualitor

Qualitor

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.21%
  • Veröffentlicht 12.12.2025 20:32:06
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security vulnerability has been detected in Qualitor up to 8.24.73. The impacted element is an unknown function of the file /Qualitor/html/bc/bcdocumento9/biblioteca/request/viewDocumento.php. Such manipulation of the argument cdscript leads to cro...

Medienbericht Exploit
  • EPSS 0.4%
  • Veröffentlicht 30.11.2025 16:02:05
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros results in co...

Exploit
  • EPSS 2.95%
  • Veröffentlicht 25.05.2025 01:15:23
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /html/ad/adconexaooffice365/request/testaConexaoOffice365.php of the component Office 365-type Connection...

Exploit
  • EPSS 2.22%
  • Veröffentlicht 31.10.2024 20:15:05
  • Zuletzt bearbeitet 01.07.2025 20:36:59

Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

Exploit
  • EPSS 3.91%
  • Veröffentlicht 31.10.2024 20:15:05
  • Zuletzt bearbeitet 01.07.2025 20:36:49

Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.

Exploit
  • EPSS 46.3%
  • Veröffentlicht 09.09.2024 18:15:03
  • Zuletzt bearbeitet 01.07.2025 20:37:06

Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

Exploit
  • EPSS 14.42%
  • Veröffentlicht 06.11.2023 06:15:40
  • Zuletzt bearbeitet 07.07.2025 18:50:25

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.