PT-2025-14780 · Projeqtor · Projeqtor
Deadmilkman
·
Published
2025-04-03
·
Updated
2025-05-14
·
CVE-2025-3169
CVSS v2.0
4.6
Medium
| Vector | AV:N/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Projeqtor versions up to 12.0.2
Description
A critical issue affects some unknown functionality of the file /tool/saveAttachment.php, where the manipulation of the
attachmentFiles argument leads to unrestricted upload. The attack can be launched remotely, but the complexity is rather high, and the exploitation is known to be difficult. The vendor notes that this issue can be exploited only on not securely installed instances, as the attachment directory should be out of web reach.Recommendations
For Projeqtor versions up to 12.0.2, upgrade to version 12.0.3 to address this issue. As a temporary workaround, consider restricting access to the /tool/saveAttachment.php file to minimize the risk of exploitation. Ensure the attachment directory is out of web reach, as advised during product installation, to prevent executable files from being executed through the web.
Exploit
Fix
RCE
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Projeqtor