Description
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.
Remediation
References
Related Vulnerabilities
WordPress Plugin Store Locator for WordPress with Google Maps-LotsOfLocales SQL Injection (3.11)
Ruby Inefficient Regular Expression Complexity Vulnerability (CVE-2023-22795)
WordPress Plugin ClickDesk Live Support-Live Chat-Help Desk Cross-Site Scripting (4.2)
MySQL CVE-2019-2695 Vulnerability (CVE-2019-2695)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4614)