PT-2025-48395 · Qualitor · Qualitor

Dante Michelon

+2

·

Published

2025-11-30

·

Updated

2025-12-07

·

CVE-2025-13792

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Qualitor versions prior to 8.20.105 and prior to 8.24.98
Description A security flaw exists in Qualitor that allows for code injection. The eval function within the file /html/st/stdeslocamento/request/getResumo.php is affected. Manipulation of the passageiros argument can lead to code injection, and remote exploitation is possible. The exploit for this issue has been publicly released.
Recommendations Qualitor versions prior to 8.20.105 should be upgraded. Qualitor versions prior to 8.24.98 should be upgraded.

Exploit

Fix

RCE

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13792

Affected Products

Qualitor