Description
qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by_extrafields[] values to trigger SQL syntax errors and extract database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Mehmet EMIROGLU
References
www.exploit-db.com/exploits/46387 (ExploitDB-46387)
qdpm.net (Official Product Homepage)
qdpm.net/download-qdpm-free-project-management (Product Reference)
www.vulncheck.com/...ion-via-search-by-extrafields-parameter (VulnCheck Advisory: qdPM 9.1 SQL Injection via search_by_extrafields Parameter)