Lucene search

K
cve[email protected]CVE-2023-45856
HistoryOct 14, 2023 - 5:15 a.m.

CVE-2023-45856

2023-10-1405:15:55
CWE-434
web.nvd.nist.gov
30
cve-2023-45856
qdpm
remote code execution
edit project
file upload
uploads uri
security vulnerability

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.7%

qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

Affected configurations

NVD
Node
qdpmqdpmMatch9.2
CPENameOperatorVersion
qdpm:qdpmqdpmeq9.2

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.7%

Related for CVE-2023-45856