Логотип exploitDog
bind:CVE-2020-26166
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26166

Количество 2

Количество 2

nvd логотип

CVE-2020-26166

больше 5 лет назад

The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-m583-fc3c-p6gh

больше 3 лет назад

The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26166

The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
github логотип
GHSA-m583-fc3c-p6gh

The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу