Showing 1 vulnerability on this page for ProjeQtOr Project Management

Signals CISA KEV Ransomware Nuclei
ProjeQtor vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ProjeQtOr Project Management 9.1.4 - Remote Code Execution

ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code execution capabilities. Attackers can upload a PHP script through the profile attachment section and execute system commands by accessing the uploaded file with a specially crafted request parameter.

CWE-434Jan 15, 2026
CVSS9.3v4.0EPSS0.381%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX