Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-25669

qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by_extrafields[] values to trigger SQL syntax errors and extract database information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.3%
CVSS Severity
CVSS v3 Score 8.2
Products affected by CVE-2019-25669
  • Qdpm » Qdpm » Version: 8.3
    cpe:2.3:a:qdpm:qdpm:8.3
  • Qdpm » Qdpm » Version: 9.0
    cpe:2.3:a:qdpm:qdpm:9.0
  • Qdpm » Qdpm » Version: 9.1
    cpe:2.3:a:qdpm:qdpm:9.1


Contact Us

Shodan ® - All rights reserved