Lucene search

K
osvGoogleOSV:GHSA-XJ4V-GP4Q-H6QQ
HistoryMay 24, 2022 - 5:43 p.m.

qcubed reflected cross-site scripting (XSS) vulnerability

2022-05-2417:43:36
Google
osv.dev
8
qcubed
cross-site scripting
vulnerability
profile page
unauthenticated attackers
authenticated users
software

AI Score

5.5

Confidence

High

EPSS

0.003

Percentile

71.7%

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

AI Score

5.5

Confidence

High

EPSS

0.003

Percentile

71.7%