Lucene search

K
cvelistMitreCVELIST:CVE-2020-26165
HistoryDec 31, 2020 - 8:38 p.m.

CVE-2020-26165

2020-12-3120:38:22
mitre
www.cve.org
2
qdpm
v9.1
php object injection
cve-2020-26165
timereportactions
executeexport
core
apps
modules

AI Score

9

Confidence

High

EPSS

0.062

Percentile

93.7%

qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.

AI Score

9

Confidence

High

EPSS

0.062

Percentile

93.7%

Related for CVELIST:CVE-2020-26165