CVE-2020-26166

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
05/10/2020
Last modified:
13/10/2020

Description

The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qdpm:qdpm:9.1:*:*:*:*:*:*:*