CVE-2020-26166
Summary
| CVE | CVE-2020-26166 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-05 12:15:00 UTC |
| Updated | 2020-10-13 15:59:00 UTC |
| Description | The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVEs/CVE-2020-26166.md at main · Kajmer/CVEs · GitHub | MISC | github.com | Third Party Advisory |
| qdPM 7.0 Release Notes - Free Project Management | MISC | qdpm.net | Release Notes, Vendor Advisory |
| qdPM - Project Management Tool | Get qdPM - Project Management Tool at SourceForge.net | MISC | sourceforge.net | Product, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.