ZipSlip Path Traversal Vulnerability in ProjeQtor by ProjeQtor
CVE-2026-41463
Key Information:
Badges
What is CVE-2026-41463?
ProjeQtor, versions 7.0 through 12.4.3, is susceptible to a ZipSlip path traversal vulnerability. This security flaw is present in the plugin's upload functionality, allowing authenticated attackers with upload permissions to exploit unvalidated archive extraction. By using specially crafted ZIP files that contain directory traversal sequences, attackers can write files outside the intended extraction directory. This exploit can ultimately lead to the deployment of a PHP web shell within a web-accessible directory, enabling remote code execution with the privileges of the web server process.
Affected Version(s)
ProjeQtor 7.0 <= 12.4.3
ProjeQtor 12.4.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
