CVE-2022-24992
HIGHqr_code_generator < 5.2.7 - Path Traversal via process.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-24992. PoCs published by esistferry.
AI-analyzed exploit summary This repository contains a writeup for CVE-2022-24992, a path traversal vulnerability in QRCDR's QR-Code generator script. The README references an external blog post for detailed information.
Description
A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
Exploits (1)
nomisec
WRITEUP
by esistferry · poc
https://github.com/esistferry/CVE-2022-24992
This repository contains a writeup for CVE-2022-24992, a path traversal vulnerability in QRCDR's QR-Code generator script. The README references an external blog post for detailed information.
Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target:
QRCDR QR-Code generator script
No auth needed
Prerequisites:
access to the vulnerable QRCDR script
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Broken Link x_refsource_misc
http://qrcdr.com
Product x_refsource_misc
https://codecanyon.net/item/qrcdr-responsive-qr-code-generator/9226839
Exploit, Mitigation, Third Party Advisory x_refsource_misc
https://n0lsec.medium.com/qrcdr-path-traversal-vulnerability-bb89acc0c100
Scores
CVSS v3
7.5
EPSS
0.0147
EPSS Percentile
70.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (1)
qr_code_generator_project/qr_code_generator
< 5.2.7
Published
Jul 25, 2022
Tracked Since
Feb 18, 2026