---
id: CVE-2025-13792
title: A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97
summary: >-
  A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97.
  Affected by this vulnerability is the function eval of the file
  /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of
  the argument passageiros …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-94
published: '2025-11-30'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13792'
references:
  - url: 'https://vuldb.com/?ctiid.333796'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333796'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.691251'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.704314'
    label: cna@vuldb.com
  - url: 'https://www.qualitor.com.br/official-security-advisory-cve-2025-13792'
    label: cna@vuldb.com
  - url: 'https://www.youtube.com/watch?v=hU8YbFc6KpI'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.0046
epssPercentile: 0.37191
ingestedAt: '2026-09-03T03:55:22.677Z'
---

## Overview

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Upgrading to version 8.20.105 and 8.24.98 addresses this issue. Upgrading the affected component is advised.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
