Description
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
Remediation
References
Related Vulnerabilities
SharePoint Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-2816)
WordPress Plugin Quick Buy For Woocommerce Arbitrary File Disclosure (2.0)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-15081)
Grafana Authentication Bypass by Spoofing Vulnerability (CVE-2023-3128)