← Vulnerability feed

Vulnerability record · CVE-2020-7246 · published 21 January 2020

CVE-2020-7246: qdPM authenticated file upload path traversal leads to RCE

Qdpm · Qdpm

qdPM 9.1 and earlier allows an authenticated user to upload a malicious PHP file through the profile photo feature. A path traversal flaw in the users['photop_preview'] delete photo function lets the attacker bypass .htaccess protection, so the uploaded PHP executes on the server. The issue is an incomplete fix for CVE-2015-3884.

8.8 CVSS 3.1 High EPSS 83% · top 0.3% CWE-22 · Path traversalCWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote code execution with public exploit code and a very high EPSS score, though it requires an authenticated low-privileged account and is not in KEV.

What it is

qdPM 9.1 and earlier allows an authenticated user to upload a malicious PHP file through the profile photo feature. A path traversal flaw in the users['photop_preview'] delete photo function lets the attacker bypass .htaccess protection, so the uploaded PHP executes on the server. The issue is an incomplete fix for CVE-2015-3884.

Impact

An attacker with a valid account gains remote code execution on the web server, leading to full compromise of the application and its data. This can extend to the underlying host depending on the web server's privileges.

Attack surface

Reached over the network through the qdPM web interface; the CVSS vector shows PR:L, so a low-privileged authenticated account is required, and no user interaction is needed. The flaw is in the profile photo upload and delete functionality.

Exploitation

Public exploit code is referenced in multiple Packet Storm and third-party advisories, and EPSS is 0.83235 (99.7th percentile), indicating a high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade qdPM to a version that fully fixes the incomplete CVE-2015-3884 remediation; if no fixed version is available, treat the product as unsupported and isolate it.
  • Restrict access to the qdPM application to trusted networks or place it behind an authenticating reverse proxy.
  • Disable PHP execution in upload and profile photo directories, and verify .htaccess or equivalent server rules cannot be bypassed by traversal.
  • Audit and remove unnecessary user accounts, and enforce least privilege for any account that can reach the profile photo feature.
  • Monitor and restrict outbound traffic from the qdPM host to limit post-exploitation activity.

Detection

  • Monitor web server logs for POST requests to profile photo upload endpoints followed by requests to PHP files in upload or user photo directories.
  • Alert on path traversal sequences such as ../ in parameters tied to the photop_preview delete function.
  • Detect newly created or modified PHP files in upload, cache, or profile photo directories.
  • Watch for unexpected child processes spawned by the web server, such as shells or command interpreters.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7246 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-45856Qdpm unrestricted file upload vulnerabilityqdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.EPSS 1.4%9.8CVE-2020-11811Qdpm unrestricted file upload vulnerabilityIn qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type va…EPSS 3.0%8.8CVE-2019-25669Qdpm sql injection vulnerabilityqdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_ext…EPSS 0.31%8.8CVE-2018-25208Qdpm sql injection vulnerabilityqdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through …EPSS 0.34%8.8CVE-2022-26180Qdpm cross-site request forgery vulnerabilityqdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.EPSS 3.8%8.8CVE-2020-26165Qdpm deserialization of untrusted data vulnerabilityqdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php beca…EPSS 2.5%8.8CVE-2015-3884Qdpm unrestricted file upload vulnerabilityUnrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pa…EPSS 14%7.5CVE-2023-45855Qdpm path traversal vulnerabilityqdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2020-7246), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.