Executive brief
QaTraq, a test management platform, contains a security flaw in its attachment handling system. An authorized user can upload malicious files, such as PHP scripts, which the server then executes. This allows an attacker to take complete control of the server, potentially leading to data theft, service disruption, or a foothold for further attacks within the corporate network.
Technical details
An unrestricted file upload vulnerability exists in QaTraq 6.9.2 within the 'Add Attachment' feature of the 'Test Script' module. The application fails to validate or restrict file extensions, allowing an authenticated user to upload executable PHP scripts. Once uploaded, these files are stored in a web-accessible directory and can be triggered via the 'View Attachment' function. This results in Remote Code Execution (RCE) with the privileges of the web server user. The vendor has reportedly not responded to disclosure attempts, and the software is considered legacy/unsupported.
Affected products
- testmanagement QaTraq 6.9.2
Timeline
- 2025-06-30: other: Vulnerability identified during internal review
- 2025-07-22: disclosed: Vendor contacted (no response received)
- 2025-11-17: advisory: CVE published