PT-2025-47158 · Unknown · Qatraq Version 6.9.2

Published

2025-11-17

·

Updated

2025-11-26

·

CVE-2025-63748

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QaTraq version 6.9.2
Description QaTraq version 6.9.2 allows authenticated users to upload arbitrary files through the “Add Attachment” feature within the “Test Script” module. The application does not restrict file types, allowing the upload of executable PHP files. Once uploaded, these files can be accessed via the “View Attachment” option, which executes the PHP payload on the server. The vulnerable functionality resides in the “Test Script” module, specifically the file upload process. The Add Attachment feature is susceptible to this issue. The uploaded files are accessible through the View Attachment option.
Recommendations QaTraq version 6.9.2: As a temporary workaround, consider restricting access to the “Test Script” module to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-63748

Affected Products

Qatraq Version 6.9.2