qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://qdpm.net/qdpm-release-notes-free-project-management | vendor advisory |
http://packetstormsecurity.com/files/160733/qdPM-9.1-PHP-Object-Injection.html | exploit vdb entry third party advisory |
http://seclists.org/fulldisclosure/2021/Jan/10 | mailing list exploit third party advisory |