Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-7246

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.935
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
References
Products affected by CVE-2020-7246
  • Qdpm » Qdpm » Version: 8.3
    cpe:2.3:a:qdpm:qdpm:8.3
  • Qdpm » Qdpm » Version: 9.0
    cpe:2.3:a:qdpm:qdpm:9.0
  • Qdpm » Qdpm » Version: 9.1
    cpe:2.3:a:qdpm:qdpm:9.1


Contact Us

Shodan ® - All rights reserved