Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sunshineotaku

#15691de 53,635
17.3CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2023-29733
7.5
2023-10-13
Qdpm · Qdpm · CVE-2023-45855
**Name of the Vulnerable Software and Affected Versions** qdPM version 9.2 **Description** The issue allows Directory Traversal, enabling the listing of files and directories by navigating to the "/uploads" URI. **Recommendations** For qdPM version 9.2, consider restricting access to the /uploads URI as a temporary workaround until a patch is available.
PT-2023-29734
9.8
2023-10-13
Qdpm · Qdpm · CVE-2023-45856
**Name of the Vulnerable Software and Affected Versions** qdPM version 9.2 **Description** The issue allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the "/uploads" URI. **Recommendations** For qdPM version 9.2, consider disabling the file upload feature in the Edit Project section until a patch is available. Restrict access to the /uploads URI to minimize the risk of exploitation. Avoid using the Add Attachments feature in the affected version to prevent potential remote code execution attacks.