PT-2026-35446 · Projeqtor · Projeqtor

Noé Susset

+1

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-41467

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ProjeQtor versions 7.0 through 12.4.3
Description A stored cross-site scripting issue exists in the file upload functionality. The checkValidFileName() function fails to restrict the upload of HTML and HTM files. Authenticated attackers can upload files containing arbitrary JavaScript through the image upload or attachment endpoints. When a user accesses the URL of the uploaded file, the embedded JavaScript executes within their browser.
Recommendations Update to version 12.4.4 or later. As a temporary workaround, restrict the use of the checkValidFileName() function or the image upload and attachment endpoints to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-41467

Affected Products

Projeqtor