Security Advisory

CVE-2023-45856

9.8
CRITICAL

Vulnerability Description

qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
Published Date October 14, 2023
Official Source NIST NVD Advisory