Description
ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by only detecting specific patterns while returning unsanitized strings without output encoding. Attackers can inject malicious payloads that bypass the filter using alternative syntax such as img tags with event handlers, which are stored and executed in the browsers of users viewing the affected content.
INFO
Published Date :
2026-04-27T15:11:12.228Z
Last Modified :
2026-04-27T15:47:24.744Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2026-41466 vulnerability.
| Vendors | Products |
|---|---|
| Projeqtor |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-41466.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact