AI Score
Confidence
High
EPSS
Percentile
93.7%
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
packetstormsecurity.com/files/160733/qdPM-9.1-PHP-Object-Injection.html
qdpm.net/qdpm-release-notes-free-project-management
seclists.org/fulldisclosure/2021/Jan/10