High severity8.2NVD Advisory· Published Mar 26, 2026· Updated Apr 20, 2026
CVE-2018-25208
CVE-2018-25208
Description
qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through filter_by parameters. Attackers can submit malicious POST requests to the timeReport endpoint with crafted filter_by[CommentCreatedFrom] and filter_by[CommentCreatedTo] parameters to execute arbitrary SQL queries and retrieve sensitive data.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/45767nvdExploitThird Party Advisory
- www.vulncheck.com/advisories/qdpm-sql-injection-via-filter-by-parametersnvdVendor Advisory
- qdpm.netnvdProduct
- qdpm.net/download-qdpm-free-project-managementnvdProduct
News mentions
0No linked articles in our index yet.