CVE-2023-47253

critical

Description

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.

References

https://www.qualitor.com.br/qualitor-8-20

https://www.qualitor.com.br/official-security-advisory-cve-2023-47253

https://www.linkedin.com/in/xvinicius/

https://www.linkedin.com/in/hairrison-wenning-4631a4124/

https://openxp.xpsec.co/blog/cve-2023-47253

Details

Source: Mitre, NVD

Published: 2023-11-06

Updated: 2025-07-07

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.93818