QCube Cross-Site-Scripting
A reflected cross-site scripting vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.
qcubedPoC 已收录
CVSS6.1EPSS 21.0%