vendor:
ProjeQtor Project Management
by:
Temel Demir
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: ProjeQtor Project Management
Affected Version From: v9.1.4
Affected Version To: v9.1.4
Patch Exists: NO
Related CWE: N/A
CPE: a:projeqtor:projeqtor_project_management:9.1.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Laragon @WIN10
2021
ProjeQtOr Project Management 9.1.4 – Remote Code Execution
A malicious file can be run with arbitrary file upload in the profile editing section. A malicious file can be created with php code and uploaded to the profile editing section. The malicious file can then be called with the .projeqtor statement added to the file extension.
Mitigation:
Restrict access to the profile editing section and ensure that only authorized personnel can access it.