Looking for the vulnerability index of Invicti's legacy products?
qdPM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-26165) - Vulnerability Database

qdPM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-26165)

Description

qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.

References

Related Vulnerabilities