Vulnerabilities (CVE)

Filtered by vendor Projeqtor Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42940 1 Projeqtor 1 Projeqtor 2022-02-18 3.5 LOW 9.9 CRITICAL
A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious JavaScript code.