Description
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.
Remediation
References
Related Vulnerabilities
Zikula Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-4729)
Roundcube Multiple Buffer Overflow Vulnerabilities (CVE-2015-2181)
Joomla! Core 3.x.x Local File Inclusion (3.0.0 - 3.9.25)
WebLogic CVE-2018-3249 Vulnerability (CVE-2018-3249)
MediaWiki Incorrect Authorization Vulnerability (CVE-2021-36132)