CVE-2025-13792

HIGH

Qualitor <8.20.104/8.24.97 - Code Injection

Title source: llm
STIX 2.1

Description

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Upgrading to version 8.20.105 and 8.24.98 addresses this issue. Upgrading the affected component is advised.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.333796
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.333796
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.691251
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.704314
Various Sources exploit media-coverage
https://www.youtube.com/watch?v=hU8YbFc6KpI

Scores

CVSS v3 7.3
EPSS 0.0040
EPSS Percentile 31.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-94
Status published
Products (50)
n/a/Qualitor 8.20.104
n/a/Qualitor 8.20.105
n/a/Qualitor 8.24.0
n/a/Qualitor 8.24.1
n/a/Qualitor 8.24.10
n/a/Qualitor 8.24.11
n/a/Qualitor 8.24.12
n/a/Qualitor 8.24.13
n/a/Qualitor 8.24.14
n/a/Qualitor 8.24.15
... and 40 more
Published Nov 30, 2025
Tracked Since Feb 18, 2026