View ProjeQtOr On SourceForge.net
ProjeQtOr - Project Management Tool
Support us on Capterra
OIN - Open Invention Network
ProjeQtOr free project management software - XSS vulnerability found in attachments - ProjeQtOr
 

XSS vulnerability found in attachments

More
20 Mar 2026 16:37 #1 by septseault
Hello,

In our version of ProjeQtOr 12.4.2 (on-premise), as well as on demo.projeqtor.org , we just found out that we can attach to a project a HTML file with some JS content and when a user (uploader or another one) try to open it in ProjeQtOr, the web page open and the JS code is executed.
It works if the HTML file contains a simple <script>alert()</script>
But we have done also a simple test to exfiltrate user cookie to an attacking server, but we don't shared it on this forum for security reasons.
We tried with Chrome and Firefox.

We deleted the file from demo.projeqtor.org to avoid any problems with other users.

Can you please fix this XSS vulnerability ?

Regards,

Please Log in or Create an account to join the conversation.

More
24 Mar 2026 15:55 #2 by babynus
Hi

Thanks for reporting the issue.
We recorded ticket on the roadmap and will fix it asap to include fix in next patch.

Babynus
Administrator of ProjeQtOr web site

Please Log in or Create an account to join the conversation.

Moderators: babynusprotion
Time to create page: 0.030 seconds

Cookies settings

×

Functional Cookies

Ce site utilise des cookies pour assurer son bon fonctionnement et ne peuvent pas être désactivés de nos systèmes. Nous ne les utilisons pas à des fins publicitaires. Si ces cookies sont bloqués, certaines parties du site ne pourront pas fonctionner.

Session

Please login to see yours activities!

Other cookies

Ce site web utilise un certain nombre de cookies pour gérer, par exemple, les sessions utilisateurs.