Vulnerabilities > Q2W3

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-47521 Cross-site Scripting vulnerability in Q2W3 Post Order
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Bond, AndreSC Q2W3 Post Order allows Reflected XSS.This issue affects Q2W3 Post Order: from n/a through 1.2.8.
network
low complexity
q2w3 CWE-79
6.1