← Back to CVE List

CVE-2020-26166

Published: 2020-10-05T12:15Z
Last Modified: 2024-11-21T05:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt