A reflected Cross-Site Scripting (XSS) vulnerability...
Moderate severity
Unreviewed
Published
Feb 8, 2025
to the GitHub Advisory Database
•
Updated Feb 8, 2025
Description
Published by the National Vulnerability Database
Feb 7, 2025
Published to the GitHub Advisory Database
Feb 8, 2025
Last updated
Feb 8, 2025
A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in QingScan <=v1.8.0. The vulnerability is caused by improper input sanitization of the query parameter, allowing an attacker to inject malicious JavaScript payloads. When a victim accesses a crafted URL containing the malicious input, the script executes in the victim's browser context.
References