vendor:
ProjeQtOr Project Management System
by:
Mirabbas Agalarov
5.5
CVSS
MEDIUM
Multiple XSS
79
CWE
Product Name: ProjeQtOr Project Management System
Affected Version From: V10.4.1
Affected Version To: V10.4.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
ProjeQtOr Project Management System V10.4.1 – Multiple XSS
Multiple XSS vulnerabilities in ProjeQtOr Project Management System V10.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cronStatus parameter in refreshCronIconStatus.php, (2) SVG file upload, or (3) destinationWidth parameter in ack.php.
Mitigation:
Update to the latest version of ProjeQtOr Project Management System