High
CVSS 8.8
Overview
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExpor...
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
This vulnerability is rated 🟠 HIGH.
Recommended actions: