Junglewise Threat Intelligence

CVE-2025-63747: QaTraq default administrative credentials in web login

CVE-2025-63747 · Severity: critical · CVSS 9.8 · Published 2025-11-17

Executive brief

QaTraq, a test management platform, contains a critical security flaw where it ships with a default administrative account (admin/admin) that is active by default. An attacker who can reach the application's login page can use these credentials to gain full control over the system. This could lead to the theft of testing data, unauthorized modification of quality assurance records, or a foothold for further attacks on the internal network.

Technical details

QaTraq 6.9.2 contains a CWE-521 (Weak Password Requirements) vulnerability due to the inclusion of a default administrative account that is not disabled or forced to change upon installation. The account uses the credentials 'admin' for both the username and password. An unauthenticated attacker with network access to the web application's login interface can use these credentials to gain full administrative privileges. This vulnerability is particularly dangerous when chained with other flaws in the legacy software, such as unrestricted file uploads, to achieve remote code execution. No patch is currently available as the vendor did not respond to disclosure attempts; users are advised to manually change the default password or decommission the software.

Affected products

  • testmanagement QaTraq 6.9.2

Timeline

  • 2025-06-30: other: Vulnerability identified during internal review
  • 2025-07-22: other: Vendor contacted
  • 2025-11-17: advisory: CVE published by MITRE

References

Related threats