CVE-2025-63748
QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, which executes the PHP payload on the server.
Published:Nov 17, 2025
Last Modified:Nov 26, 2025
EPS:Nov 17, 2025
EPSS Score:0.00047
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Qatraq
Product
Qatraq
Qatraq
Qatraq
Vendor
Testmanagement
Product
Qatraq
Testmanagement
Qatraq
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
