CVE-2019-25669
- EPSS 0.03%
- Veröffentlicht 05.04.2026 20:45:22
- Zuletzt bearbeitet 09.04.2026 19:38:38
qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by...
CVE-2018-25208
- EPSS 0.09%
- Veröffentlicht 26.03.2026 11:39:54
- Zuletzt bearbeitet 20.04.2026 14:09:24
qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through filter_by parameters. Attackers can submit malicious POST requests to the timeReport endpoint with cr...
CVE-2023-45856
- EPSS 6.59%
- Veröffentlicht 14.10.2023 05:15:55
- Zuletzt bearbeitet 21.11.2024 08:27:29
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
CVE-2023-45855
- EPSS 79.3%
- Veröffentlicht 14.10.2023 05:15:55
- Zuletzt bearbeitet 21.11.2024 08:27:29
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
CVE-2022-26180
- EPSS 0.45%
- Veröffentlicht 08.04.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:33
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
CVE-2020-19515
- EPSS 4.53%
- Veröffentlicht 09.09.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:09:14
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
CVE-2020-18468
- EPSS 0.35%
- Veröffentlicht 26.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:38
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.
CVE-2020-26165
- EPSS 1.13%
- Veröffentlicht 31.12.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:25
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
CVE-2020-26166
- EPSS 0.26%
- Veröffentlicht 05.10.2020 12:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:25
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, o...
CVE-2020-11814
- EPSS 0.29%
- Veröffentlicht 16.04.2020 19:15:27
- Zuletzt bearbeitet 21.11.2024 04:58:41
A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websites.