Description
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious file.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Dynamic Keywords Injector Cross-Site Request Forgery (2.3.15)
WordPress Plugin MX Time Zone Clocks Cross-Site Scripting (3.4)
WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36155)
Oracle Application Server CVE-2009-1011 Vulnerability (CVE-2009-1011)