PT-2026-35446 · Projeqtor · Projeqtor
Noé Susset
+1
·
Published
2026-04-27
·
Updated
2026-04-27
·
CVE-2026-41467
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ProjeQtor versions 7.0 through 12.4.3
Description
A stored cross-site scripting issue exists in the file upload functionality. The
checkValidFileName() function fails to restrict the upload of HTML and HTM files. Authenticated attackers can upload files containing arbitrary JavaScript through the image upload or attachment endpoints. When a user accesses the URL of the uploaded file, the embedded JavaScript executes within their browser.Recommendations
Update to version 12.4.4 or later.
As a temporary workaround, restrict the use of the
checkValidFileName() function or the image upload and attachment endpoints to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Projeqtor