CVE-2025-63747

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain administrative access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:testmanagement:qatraq:6.9.2:*:*:*:*:*:*:*

History

26 Nov 2025, 15:50

Type Values Removed Values Added
First Time Testmanagement qatraq
Testmanagement
CPE cpe:2.3:a:testmanagement:qatraq:6.9.2:*:*:*:*:*:*:*
References () http://qatraq.com - () http://qatraq.com - Broken Link
References () https://bitsbyamg.com/blog/post/2025/10/19/qatraq-692-default-creds-and-file-upload-rce - () https://bitsbyamg.com/blog/post/2025/10/19/qatraq-692-default-creds-and-file-upload-rce - Exploit, Third Party Advisory

17 Nov 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-521

17 Nov 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-17 16:15

Updated : 2025-11-26 15:50


NVD link : CVE-2025-63747

Mitre link : CVE-2025-63747

CVE.ORG link : CVE-2025-63747


JSON object : View

Products Affected

testmanagement

  • qatraq
CWE
CWE-521

Weak Password Requirements