ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip...
High severity
Unreviewed
Published
Apr 27, 2026
to the GitHub Advisory Database
•
Updated Apr 27, 2026
Description
Published by the National Vulnerability Database
Apr 27, 2026
Published to the GitHub Advisory Database
Apr 27, 2026
Last updated
Apr 27, 2026
ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outside the intended extraction directory by crafting ZIP archives with directory traversal sequences. Attackers can exploit unvalidated archive extraction to write a PHP webshell to a web-accessible directory and achieve remote code execution with the privileges of the web server process.
References