CVE-2023-45856 Information

Description

qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

Reference

https://github.com/SunshineOtaku/Report-CVE/blob/main/qdPM/9.2/RCE.md https://qdpm.net

Share on: