Description
QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to inject malicious script code through path parameter manipulation. Attackers can exploit the vulnerability to execute persistent cross-site scripting attacks, potentially leading to session hijacking and application module manipulation.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
2.0.1
Credits
Vulnerability-Lab [Research Team]
References
www.vulnerability-lab.com/get_content.php?id=2326 (Vulnerability Lab Advisory)
apps.apple.com/us/app/qwe/id935520103 (Product Homepage)
www.vulncheck.com/...nt-xss-vulnerability-via-path-parameter (VulnCheck Advisory: QWE DL 2.0.1 Persistent XSS Vulnerability via Path Parameter)