Looking for the vulnerability index of Invicti's legacy products?
ProjectSend Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-7202) - Vulnerability Database

ProjectSend Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-7202)

Description

An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.

References