Testmanagement Qatraq vulnerabilities
2 known vulnerabilities affecting testmanagement/qatraq.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2025-63747P2CRITICALCVSS 9.8v6.9.22025-11-17
CVE-2025-63747 [CRITICAL] CWE-521 CVE-2025-63747: QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installation
QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain administrative access.
nvd
CVE-2025-63748P3HIGHCVSS 8.8v6.9.22025-11-17
CVE-2025-63748 [HIGH] CWE-434 CVE-2025-63748: QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature i
QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, which executes the PHP payload on the server.
nvd