ZipSlip Path Traversal Vulnerability in ProjeQtor by ProjeQtor
CVE-2026-41463
8.7HIGH
What is CVE-2026-41463?
ProjeQtor, versions 7.0 through 12.4.3, is susceptible to a ZipSlip path traversal vulnerability. This security flaw is present in the plugin's upload functionality, allowing authenticated attackers with upload permissions to exploit unvalidated archive extraction. By using specially crafted ZIP files that contain directory traversal sequences, attackers can write files outside the intended extraction directory. This exploit can ultimately lead to the deployment of a PHP web shell within a web-accessible directory, enabling remote code execution with the privileges of the web server process.
Affected Version(s)
ProjeQtor 7.0 <= 12.4.3
ProjeQtor 12.4.4
