Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-26165

qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.036
EPSS Ranking 87.1%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2020-26165
  • Qdpm » Qdpm » Version: 8.3
    cpe:2.3:a:qdpm:qdpm:8.3
  • Qdpm » Qdpm » Version: 9.0
    cpe:2.3:a:qdpm:qdpm:9.0
  • Qdpm » Qdpm » Version: 9.1
    cpe:2.3:a:qdpm:qdpm:9.1


Contact Us

Shodan ® - All rights reserved