Description
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Visual Email Designer for WooCommerce SQL Injection (1.7.1)
Moodle Uncontrolled Resource Consumption Vulnerability (CVE-2021-20185)
MySQL Resource Management Errors Vulnerability (CVE-2010-3678)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-5379)