Description
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.
Remediation
References
Related Vulnerabilities
OpenSSL Cryptographic Issues Vulnerability (CVE-2013-6450)
WordPress Plugin WP-Filebase Download Manager Remote Code Execution (0.3.0.03)
WordPress Plugin Event List PHP Object Injection (0.7.10)
WordPress Plugin Nextend Google Connect Cross-Site Scripting (1.5.2)
WordPress Plugin PDF & Print by BestWebSoft Cross-Site Scripting (2.0.2)