Cross-Site Scripting Vulnerability in ProjectSend by Ignacionelson
CVE-2017-9786
6.1MEDIUM
What is CVE-2017-9786?
A Cross-Site Scripting (XSS) vulnerability exists in ProjectSend prior to a specific GitHub commit, allowing remote attackers to inject arbitrary web scripts or HTML code through the Description field in the My Account Name update. This flaw is associated with files home.php and actions-log.php, potentially compromising user data and application integrity.