Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.938
EPSS Ranking 99.9%