Forum

XSS vulnerability f...
 
Notifications
Retirer tout

XSS vulnerability found in attachments

2 Posts
2 Utilisateurs
0 Reactions
263 Vu
(@septseault)
Posts: 3
Active Member
Début du sujet
 
[#10081]

Hello,

In our version of ProjeQtOr 12.4.2 (on-premise), as well as on demo.projeqtor.org, we just found out that we can attach to a project a HTML file with some JS content and when a user (uploader or another one) try to open it in ProjeQtOr, the web page open and the JS code is executed.
It works if the HTML file contains a simple alert()
But we have done also a simple test to exfiltrate user cookie to an attacking server, but we don't shared it on this forum for security reasons.
We tried with Chrome and Firefox.

We deleted the file from demo.projeqtor.org to avoid any problems with other users.

Can you please fix this XSS vulnerability ?

Regards,


 
Posté : 20/03/2026 6:37 pm
(@babynus)
Posts: 14952
Membre Admin
 

Hi

Thanks for reporting the issue.
We recorded ticket on the roadmap and will fix it asap to include fix in next patch.


 
Posté : 24/03/2026 5:55 pm
Share:
Retour en haut