ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7202 - Vulnerability Database

ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7202

Medium
Reference: CVE-2018-7202
Title: ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

An issue was discovered in ProjectSend before r1053. XSS exists in the quotNamequot field on the My Account page.