PT-2026-5574 · Qwe Dl · Qwe Dl
Published
2026-02-01
·
Updated
2026-02-01
·
CVE-2023-54343
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
QWE DL version 2.0.1
Description
The QWE DL mobile web application has a persistent input validation issue. Remote attackers can inject malicious script code by manipulating a path parameter. This allows for persistent cross-site scripting (XSS) attacks, which could lead to session hijacking and application module manipulation. The application’s path parameter does not properly sanitize user-supplied input, allowing attackers to inject arbitrary scripts that are then stored and executed by other users.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider implementing robust input validation and output encoding mechanisms to prevent the injection of malicious scripts.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qwe Dl