testmanagement qatraq の CVE(2 件)

CVE 件数: 2 CPE versions: View versions table

概要

本ページは testmanagement qatraq に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 12 / 2 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-63748 QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, which executes the PHP payload on the server. [email protected] 8.8 0.36% 2025-11-17 2025-11-26
CVE-2025-63747 QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain administrative access. [email protected] 9.8 0.39% 2025-11-17 2025-11-26
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence