Vulnerability Description
A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /html/ad/adconexaooffice365/request/testaConexaoOffice365.php of the component Office 365-type Connection Handler. The manipulation of the argument nmconexao leads to command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 8.20.56 and 8.24.31 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualitor | Qualitor | 8.20 |
Related Weaknesses (CWE)
References
- https://gist.githubusercontent.com/MatheuZSecurity/fe221fd5b2e5393abf76be42f11f5Broken Link
- https://vuldb.com/?ctiid.310220Permissions RequiredVDB Entry
- https://vuldb.com/?id.310220Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.572477Third Party AdvisoryVDB Entry
- https://www.youtube.com/watch?v=Dq4C5s9UwyoExploit
FAQ
What is CVE-2025-5139?
CVE-2025-5139 is a vulnerability with a CVSS score of 5.6 (MEDIUM). A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /html/ad/adconexaooffice365/request/testaConexaoOffice3...
How severe is CVE-2025-5139?
CVE-2025-5139 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-5139?
Check the references section above for vendor advisories and patch information. Affected products include: Qualitor Qualitor.