SunshineOtaku

2 exploits Active since Oct 2023
CVE-2023-45855 WRITEUP HIGH WRITEUP
qdPM 9.2 - Path Traversal via /uploads URI
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
CVSS 7.5
CVE-2023-45856 WRITEUP CRITICAL WRITEUP
qdPM 9.2 - Remote Code Execution via Unrestricted PHP File Upload
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
CVSS 9.8