CVE-2020-11811General(qdpm / qdpm)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious file.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qdpm

Threat summary

  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-02-25); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
qdpm

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-25: 1Mentions · 2026-04-12: 1Mentions · 2026-04-17: 1Mentions · 2026-05-26: 1Mentions · 2026-06-17: 1Mentions · 2026-07-27: 1Technical Details · 2026-05-26: 102-2504-1204-1705-2606-1707-27
Signal classification2 categories
General
466.7%
Disclosure
233.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-02-251
General1
2026-04-121
Disclosure1
2026-04-171
General1
2026-05-261
General1
2026-06-171
General1
2026-07-271
Disclosure1
Full discourse6 posts
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en un archivo .php en el servidor en la capacidad Add Profile Photo en qdPM (CVE-2020-11811) https://ciberseguridadhoy.es/vulnerabilidad-en-un-archivo-php-en-el-servidor-en-la-capacidad-add-profile-photo-en-qdpm-cve-2020-11811/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The article briefly mentions a vulnerability (CVE‑2020‑11811) in the Add Profile Photo feature of qdPM but provides no detailed technical information, PoC, exploitation evidence, or patch notice.

    0001028
    236 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    Disclosure

    Vulnerabilidad en un archivo .php en el servidor en la capacidad Add Profile Photo en qdPM (CVE-2020-11811) https://ciberseguridadhoy.es/vulnerabilidad-en-un-archivo-php-en-el-servidor-en-la-capacidad-add-profile-photo-en-qdpm-cve-2020-11811/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The text announces a vulnerability (CVE-2020-11811) in the Add Profile Photo feature of qdPM, providing an article link but lacking technical details, exploit code, or patch information.

    0000027
    236 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en un archivo .php en el servidor en la capacidad Add Profile Photo en qdPM (CVE-2020-11811) https://ciberseguridadhoy.es/vulnerabilidad-en-un-archivo-php-en-el-servidor-en-la-capacidad-add-profile-photo-en-qdpm-cve-2020-11811/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The post cites CVE-2020-11811 as a vulnerability in a PHP file used by qdPM's Add Profile Photo feature, but it does not provide details about PoC availability, exploits, or patches.

    0000041
    238 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en un archivo .php en el servidor en la capacidad Add Profile Photo en qdPM (CVE-2020-11811) https://ciberseguridadhoy.es/vulnerabilidad-en-un-archivo-php-en-el-servidor-en-la-capacidad-add-profile-photo-en-qdpm-cve-2020-11811/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The text references a webpage describing CVE‑2020‑11811, mentioning a PHP file vulnerability in the Add Profile Photo feature of qdPM, but provides no technical, exploit, or mitigation details.

    0000038
    238 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    Disclosure

    Vulnerabilidad en un archivo .php en el servidor en la capacidad Add Profile Photo en qdPM (CVE-2020-11811) https://ciberseguridadhoy.es/vulnerabilidad-en-un-archivo-php-en-el-servidor-en-la-capacidad-add-profile-photo-en-qdpm-cve-2020-11811/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The article announces CVE‑2020‑11811—a PHP file vulnerability in qdPM’s Add Profile Photo feature—without providing explicit exploit code, PoC, or remediation details.

    0000035
    238 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en un archivo .php en el servidor en la capacidad Add Profile Photo en qdPM (CVE-2020-11811) https://ciberseguridadhoy.es/vulnerabilidad-en-un-archivo-php-en-el-servidor-en-la-capacidad-add-profile-photo-en-qdpm-cve-2020-11811/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The text merely cites a CVE and links to an article, offering no concrete details on exploitation, patches, or technical aspects.

    0000039
    237 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqdpmqdpm9.1--

Explore more