Description
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Comment and Review Spam Control for WooCommerce Security Bypass (1.4.2)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2203)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2016-5734)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-8098)