vendor:
qdPM
by:
Kishan Lal Choudhary
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: qdPM
Affected Version From: 9.1
Affected Version To: 9.1
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:a:qdpm:qdpm:9.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
qdPM 9.1 – ‘cfg[app_app_name]’ Persistent Cross-Site Scripting
The form parameter 'cfg[app_app_name]' is vulnerable to stored cross site scripting. An attacker can inject malicious JavaScript code into the parameter which will be executed when the page is loaded.
Mitigation:
Input validation should be used to prevent malicious code from being injected into the parameter.