Description
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
Remediation
References
Related Vulnerabilities
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-28129)
WordPress Plugin My Tickets Security Bypass (1.9.11)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0123)
Oracle JRE CVE-2013-0429 Vulnerability (CVE-2013-0429)
MySQL Resource Management Errors Vulnerability (CVE-2010-3677)