Hello team ProjeQtOr,
I have previously tried contacting you through the website's contact form, as well as the support email address, but I sadly haven't received a response.
I had also tried making an account here (~2 months ago), but I had an issue with the captcha which prevented me from doing so.
Now that I came back to try again, I was finally able to create an account, so I will try to get your attention here.
In a security audit I recently conducted for a client, I had discovered 2 XSS vulnerabilities (one of them is tracked as CVE-2023-49034, the other turned out to be an already existing CVEID), which I verified are still affecting the 11.0.2 version of ProjeQtOr (latest at the time of writing).
I have also noticed that there's code that tries to prevent this specific kind vulnerabilities, but it turned out to be very easy to bypass unfortunately.
I would love to exchange more about this so that we can help come up with a foolproof fix - I already have a few ideas of some PHP libraries that can be used to effectively fix the issue.
Looking forward to hearing from you.
Kind regards,
Sami