PT-2026-26636 · Qhora · Qhora

Published

2026-03-20

·

Updated

2026-03-23

·

CVE-2025-62846

CVSS v4.0

7.3

High

AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U
Name of the Vulnerable Software and Affected Versions QHora versions prior to 2.6.2.007
Description An SQL injection issue exists in QHora. A local attacker with administrator privileges can exploit this to execute unauthorized code or commands. The vulnerability allows for the execution of arbitrary code or commands.
Recommendations Update to QHora version 2.6.2.007 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-62846

Affected Products

Qhora