CVE-2014-8266
01.02.2015, 02:59
Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body field.
| Vendor | Product | Version |
|---|---|---|
| qpr | portal | 𝑥 ≤ 2014.1.1 |
𝑥
= Vulnerable software versions