Hello,
In our version of ProjeQtOr 12.4.2 (on-premise), as well as on demo.projeqtor.org, we just found out that we can attach to a project a HTML file with some JS content and when a user (uploader or another one) try to open it in ProjeQtOr, the web page open and the JS code is executed.
It works if the HTML file contains a simple alert()
But we have done also a simple test to exfiltrate user cookie to an attacking server, but we don't shared it on this forum for security reasons.
We tried with Chrome and Firefox.
We deleted the file from demo.projeqtor.org to avoid any problems with other users.
Can you please fix this XSS vulnerability ?
Regards,
Hi
Thanks for reporting the issue.
We recorded ticket on the roadmap and will fix it asap to include fix in next patch.