ZipSlip Path Traversal Vulnerability in ProjeQtor by ProjeQtor
CVE-2026-41463

8.7HIGH

Key Information:

Vendor

Projeqtor

Status
Vendor
CVE Published:
27 April 2026

What is CVE-2026-41463?

ProjeQtor, versions 7.0 through 12.4.3, is susceptible to a ZipSlip path traversal vulnerability. This security flaw is present in the plugin's upload functionality, allowing authenticated attackers with upload permissions to exploit unvalidated archive extraction. By using specially crafted ZIP files that contain directory traversal sequences, attackers can write files outside the intended extraction directory. This exploit can ultimately lead to the deployment of a PHP web shell within a web-accessible directory, enabling remote code execution with the privileges of the web server process.

Affected Version(s)

ProjeQtor 7.0 <= 12.4.3

ProjeQtor 12.4.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yassine Damiri
Noé Susset
.