CVE-2025-63748
Last modified
CVE-2025-63748 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, which executes the PHP payload on the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Testmanagement | Qatraq | 6.9.2 |
References
- https://bitsbyamg.com/blog/post/2025/10/19/qatraq-692-default-creds-and-file-upload-rceExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-63748?
How severe is CVE-2025-63748?
How do I fix CVE-2025-63748?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-63740SQL Injection vulnerability in function getselectdataAjax in…4.3
- CVE-2025-63742SQL Injection vulnerability in function setwxqyAction in fil…9.8
- CVE-2025-63743Cross-Site Scripting vulnerability in the Snipe-IT web-based…5.4
- CVE-2025-63744A NULL pointer dereference vulnerability was discovered in r…4.3
- CVE-2025-63745A NULL pointer dereference vulnerability was discovered in r…5.5
- CVE-2025-63747QaTraq 6.9.2 ships with administrative account credentials w…9.8
- CVE-2025-63749pnetlab 5.3.11 is vulnerable to Command Injection via the qe…6.5
- CVE-2025-6375A vulnerability was found in poco up to 1.14.1. It has been …5.5
- CVE-2025-63750Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE…
- CVE-2025-63757Integer overflow vulnerability in the yuv2ya16_X_c_template …7.5
- CVE-2025-6376A remote code execution security issue exists in the Rockwel…7.8
- CVE-2025-6377A remote code execution security issue exists in the Rockwel…7.8
Are you affected by CVE-2025-63748?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
