CVE-2025-63747
QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain administrative access.
Published:Nov 17, 2025
Last Modified:Nov 26, 2025
EPS:Nov 17, 2025
EPSS Score:0.00054
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Qatraq
Product
Qatraq
Qatraq
Qatraq
Vendor
Testmanagement
Product
Qatraq
Testmanagement
Qatraq
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
