CVE-2023-47253
9.8
CRITICAL · CVSS 3.1 · EPSS 14.3% (pctl 97)
Patch early
EPSS 14.3% — above the 10% action threshold.
Description
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 14.31% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-11-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| qualitor | qualitor |
References
- https://openxp.xpsec.co/blog/cve-2023-47253
- https://www.linkedin.com/in/hairrison-wenning-4631a4124/
- https://www.linkedin.com/in/xvinicius/
- https://www.qualitor.com.br/official-security-advisory-cve-2023-47253
- https://www.qualitor.com.br/qualitor-8-20
- https://openxp.xpsec.co/blog/cve-2023-47253
- https://www.linkedin.com/in/hairrison-wenning-4631a4124/
- https://www.linkedin.com/in/xvinicius/
- https://www.qualitor.com.br/qualitor-8-20
→ the Explorer · watch your stack · NVD