vendor:
qdPM
by:
Mehmet EMIROGLU
7.5
CVSS
HIGH
SQL Injection
CWE
Product Name: qdPM
Affected Version From: 9.1
Affected Version To: 9.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Wamp64, @Win
2019
qdPM 9.1 – ‘search_by_extrafields[]’ SQL Injection
The qdPM version 9.1 is vulnerable to SQL Injection. By manipulating the 'search_by_extrafields[]' parameter in a POST request, an attacker can inject malicious SQL code, leading to unauthorized access or data manipulation.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, users are advised to update to the latest version of qdPM and sanitize user inputs before executing SQL queries.