Description
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4153 | In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious file. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:42:00.533Z
Reserved: 2020-04-16T00:00:00.000Z
Link: CVE-2020-11811
No data.
Status : Modified
Published: 2020-04-16T19:15:27.073
Modified: 2024-11-21T04:58:40.740
Link: CVE-2020-11811
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD