Home/Product/qdpm
Product

qdpm

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-25669
<= 9.1
qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code throug
8.2HIGH
CVE-2018-25208
<= 9.1
qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injectin
8.2HIGH
CVE-2023-45856
all versions
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads U
9.8CRITICAL
CVE-2023-45855
all versions
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
7.5HIGH
CVE-2022-26180
all versions
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
8.8HIGH
CVE-2020-19515
all versions
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
6.1MEDIUM
CVE-2020-18468
all versions
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page under the General me
5.4MEDIUM
CVE-2020-26165
<= 9.1
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/act
8.8HIGH
CVE-2020-26166
all versions
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to injec
5.4MEDIUM
CVE-2020-11814
all versions
A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicio
5.4MEDIUM
CVE-2020-11811
all versions
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a craf
9.8CRITICAL
CVE-2020-7246
<= 9.1
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via t
8.8HIGH
CVE-2019-8391
all versions
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
6.1MEDIUM
CVE-2019-8390
all versions
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
6.1MEDIUM
CVE-2015-3884
<= 9.1
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, a
8.8HIGH
CVE-2015-3883
all versions
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via
6.1MEDIUM
CVE-2015-3882
all versions
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which revea
5.3MEDIUM
CVE-2015-3881
all versions
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/
7.5HIGH
threatengine.sh