HIGH🇵🇱 Wersja polska

CVE-2017-11760

CVSS 8.8v3.0pub. 2017-07-31upd. 2026-05-13

uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concatenated image data and script data, as demonstrated by uploading as an image within the description text area.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Projeqtor

    APP
    Projeqtor
    ≤ 6.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-42940CRITICAL9.9PL ✓same product

Stored XSS przez upload pliku SVG w Projeqtor 9.3.1

CVE-2024-29387HIGH8.8same product

projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component...

CVE-2018-18924HIGH8.8same product

The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a ....

CVE-2013-6164HIGH7.5same product

SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execut...

CVE-2024-29386MEDIUM5.4same product

projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/critica...