Skip to main content

CVE-2020-7246

8.8
HIGHCVSS v3.1 Base Score
90.44%
HIGH RiskEPSS (100th percentile)

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.

Published: 1/21/2020
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

90.44%HIGH Exploitation Risk
100th percentile

This vulnerability has a 90.44% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

Related Vulnerabilities