High severity8.2NVD Advisory· Published Apr 5, 2026· Updated Apr 9, 2026
CVE-2019-25669
CVE-2019-25669
Description
qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by_extrafields[] values to trigger SQL syntax errors and extract database information.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/46387nvdExploitVDB Entry
- www.vulncheck.com/advisories/qdpm-sql-injection-via-search-by-extrafields-parameternvdThird Party Advisory
- qdpm.netnvdProduct
- qdpm.net/download-qdpm-free-project-managementnvdProduct
News mentions
0No linked articles in our index yet.