CVE-2021-42940

A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious JavaScript code.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:projeqtor:projeqtor:*:*:*:*:*:*:*:*

Information

Published : 2022-02-11 08:15

Updated : 2022-02-17 17:59


NVD link : CVE-2021-42940

Mitre link : CVE-2021-42940


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

projeqtor

  • projeqtor