Vulnerabilities > Qdpm > Qdpm > 9.2

DATE CVE VULNERABILITY TITLE RISK
2023-10-14 CVE-2023-45855 Path Traversal vulnerability in Qdpm 9.2
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
network
low complexity
qdpm CWE-22
7.5
2023-10-14 CVE-2023-45856 Unrestricted Upload of File with Dangerous Type vulnerability in Qdpm 9.2
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
network
low complexity
qdpm CWE-434
critical
9.8
2022-04-08 CVE-2022-26180 Cross-Site Request Forgery (CSRF) vulnerability in Qdpm 9.2
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
network
qdpm CWE-352
6.8