📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 7h Global general Technology and Artificial Intelligence HIGH 8h Global vulnerability Higher Education CRITICAL 17h Global data_breach Government HIGH 18h Global supply_chain Software Development and Open Source Communities CRITICAL 18h Global malware Software Development CRITICAL 18h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 19h Global apt Critical Infrastructure CRITICAL 19h Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 7h Global general Technology and Artificial Intelligence HIGH 8h Global vulnerability Higher Education CRITICAL 17h Global data_breach Government HIGH 18h Global supply_chain Software Development and Open Source Communities CRITICAL 18h Global malware Software Development CRITICAL 18h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 19h Global apt Critical Infrastructure CRITICAL 19h Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 7h Global general Technology and Artificial Intelligence HIGH 8h Global vulnerability Higher Education CRITICAL 17h Global data_breach Government HIGH 18h Global supply_chain Software Development and Open Source Communities CRITICAL 18h Global malware Software Development CRITICAL 18h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 19h Global apt Critical Infrastructure CRITICAL 19h
Vulnerabilities

CVE-2026-41463

High
CWE-22 — Weakness Type
Published: Apr 27, 2026  ·  Modified: May 4, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outside the intended extraction directory by crafting ZIP archives with directory traversal sequences. Attackers can exploit unvalidated archive extraction to write a PHP webshell to a web-accessible directory and achieve remote code execution with the privileges of the web server process.

🤖 AI Executive Summary

ProjeQtor versions 7.0-12.4.3 contain a critical ZipSlip path traversal vulnerability in plugin upload functionality that allows authenticated attackers to write arbitrary files outside the intended directory. Attackers can upload malicious ZIP archives containing directory traversal sequences to deploy PHP webshells and achieve remote code execution with web server privileges. This vulnerability poses significant risk to Saudi organizations using ProjeQtor for project management, particularly those with internet-facing instances.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 30, 2026 23:48
🇸🇦 Saudi Arabia Impact Assessment
High impact for Saudi government agencies, consulting firms, and construction/engineering companies using ProjeQtor for project management. Government entities under NCA oversight face critical risk if ProjeQtor instances are internet-facing. Saudi construction and engineering sectors (particularly those supporting ARAMCO, NEOM, and Vision 2030 projects) are at elevated risk. Financial services firms using ProjeQtor for project tracking could face data exfiltration and compliance violations under SAMA regulations. Telecom sector (STC, Mobily) project management systems may be compromised. The vulnerability requires authenticated access but poses RCE risk with web server privileges, potentially leading to lateral movement within organizational networks.
🏢 Affected Saudi Sectors
Government (NCA-regulated entities) Construction and Engineering (NEOM, Vision 2030 projects) Banking and Financial Services (SAMA-regulated) Energy (ARAMCO and subsidiaries) Telecommunications (STC, Mobily, Zain) Healthcare (MOH facilities) Consulting and Professional Services Real Estate and Property Development
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all ProjeQtor instances in your environment (versions 7.0-12.4.3) and document their exposure level (internet-facing vs. internal)
2. Restrict plugin upload functionality to trusted administrators only; disable for standard users immediately
3. Implement network segmentation to limit ProjeQtor access to authorized personnel only
4. Review access logs for suspicious plugin uploads or ZIP file submissions in the past 90 days
5. Monitor web server directories for unexpected PHP files or suspicious file modifications

COMPENSATING CONTROLS (until patch available):
6. Implement Web Application Firewall (WAF) rules to block ZIP uploads containing directory traversal patterns (../, ..\ sequences)
7. Configure file upload restrictions at the web server level to prevent PHP execution in upload directories
8. Use AppArmor/SELinux to restrict web server process file write permissions to designated directories only
9. Implement strict input validation on all archive extraction operations
10. Enable detailed logging and alerting for plugin upload activities

DETECTION RULES:
11. Monitor for HTTP POST requests to plugin upload endpoints with Content-Type: application/zip
12. Alert on ZIP files containing path traversal sequences in filenames (../, ..\ , %2e%2e)
13. Monitor for unexpected PHP file creation in web-accessible directories
14. Track failed and successful plugin uploads with timestamps and user accounts
15. Monitor web server error logs for extraction-related errors

PATCHING STRATEGY:
16. Contact ProjeQtor vendor for security patch availability timeline
17. Prepare isolated test environment for patch validation
18. Plan upgrade to patched version as soon as available
19. If no patch forthcoming, evaluate alternative project management solutions
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع نسخ ProjeQtor في بيئتك (الإصدارات 7.0-12.4.3) وتوثيق مستوى التعرض (متصل بالإنترنت مقابل داخلي)
2. قيد وظيفة تحميل المكونات الإضافية للمسؤولين الموثوقين فقط؛ عطلها للمستخدمين العاديين فوراً
3. تنفيذ تقسيم الشبكة لتحديد وصول ProjeQtor للموظفين المصرح لهم فقط
4. راجع سجلات الوصول للتحميلات المريبة للمكونات الإضافية أو تقديمات ملفات ZIP في آخر 90 يوماً
5. راقب أدلة خادم الويب للملفات PHP غير المتوقعة أو تعديلات الملفات المريبة

الضوابط التعويضية (حتى توفر التصحيح):
6. تنفيذ قواعد جدار حماية تطبيقات الويب (WAF) لحظر تحميلات ZIP التي تحتوي على أنماط اجتياز الدليل (../ و..\ التسلسلات)
7. تكوين قيود تحميل الملفات على مستوى خادم الويب لمنع تنفيذ PHP في أدلة التحميل
8. استخدام AppArmor/SELinux لتقييد أذونات كتابة ملفات عملية خادم الويب للأدلة المعينة فقط
9. تنفيذ التحقق الصارم من المدخلات على جميع عمليات استخراج الأرشيف
10. تفعيل السجلات التفصيلية والتنبيهات لأنشطة تحميل المكونات الإضافية

قواعد الكشف:
11. راقب طلبات HTTP POST لنقاط نهاية تحميل المكونات الإضافية مع Content-Type: application/zip
12. تنبيه على ملفات ZIP التي تحتوي على تسلسلات اجتياز المسار في أسماء الملفات (../ و..\ و%2e%2e)
13. راقب إنشاء ملفات PHP غير المتوقعة في الأدلة التي يمكن الوصول إليها عبر الويب
14. تتبع تحميلات المكونات الإضافية الفاشلة والناجحة مع الطوابع الزمنية وحسابات المستخدمين
15. راقب سجلات خطأ خادم الويب للأخطاء المتعلقة بالاستخراج

استراتيجية التصحيح:
16. اتصل بمورد ProjeQtor للحصول على جدول زمني لتوفر التصحيح الأمني
17. تحضير بيئة اختبار معزولة للتحقق من صحة التصحيح
18. خطط للترقية إلى الإصدار المصحح بمجرد توفره
19. إذا لم يكن هناك تصحيح قادم، قيم حلول إدارة المشاريع البديلة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.12.3.1 - Segregation of duties in system access and change management A.14.2.1 - Secure development policy and procedures A.14.2.5 - Secure development environment A.12.4.1 - Event logging and monitoring A.12.4.3 - Administrator and operator logging A.13.1.3 - Segregation of networks
🔵 SAMA CSF
ID.AM-2: Software and hardware inventory PR.AC-1: Access control policy and procedures PR.AC-4: Access rights and privileges DE.CM-1: System monitoring DE.CM-3: Unauthorized software detection RS.MI-2: Incident response procedures
🟡 ISO 27001:2022
A.6.1.2 - Information security roles and responsibilities A.8.1.1 - User endpoint devices A.12.2.1 - Segregation of networks A.12.4.1 - Event logging A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy
🟣 PCI DSS v4.0.1
Requirement 1.1 - Network segmentation Requirement 6.2 - Security patches Requirement 10.2 - Logging and monitoring Requirement 11.2 - Vulnerability scanning
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-22
EPSS0.42%
Exploit No
Patch ✗ No
Published 2026-04-27
Source Feed nvd
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-22
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.