WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/qbittorrent/qBittorrent/commit/6ca3e4f094da0a0017cb2d483ec1db6176bb0b16 | patch |
http://www.securityfocus.com/bid/96758 | vdb entry |
https://www.qbittorrent.org/news.php | patch release notes |