Description
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2022-21306 Vulnerability (CVE-2022-21306)
WordPress Plugin Augmented reality Unspecified Vulnerability (1.2.0)
WordPress Plugin PowerPack Lite for Beaver Builder Local File Inclusion (1.3.0.3)
PostgreSQL Other Vulnerability (CVE-2007-0556)
Oracle Database Server CVE-2010-2411 Vulnerability (CVE-2010-2411)