S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 1, 2024

CVE-2019-8390 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in qdPM affects v. 9.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-8390
6.1
CVSS

qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

qdPM, or Quick Due Project Management, is web-based software designed for managing projects. It allows users to create, assign, and track tasks, as well as set project budgets and timelines. qdPM also provides collaboration tools, such as discussion boards and file sharing, to facilitate teamwork. The software boasts useful features, such as role-based access control and customizable dashboards.

However, despite qdPM's benefits, it is not immune to cyber vulnerabilities. One such vulnerability is CVE-2019-8390, which was detected in qdPM version 9.1. This weakness is a Cross-site Scripting (XSS) vulnerability found in the search[keywords] parameter of the software.

Exploitation of this vulnerability allows an attacker to execute malicious JavaScript code in the victim's browser without their knowledge. This action can result in the theft of sensitive data, such as login credentials or financial information. Furthermore, this type of attack can result in the complete takeover of a website, enabling an attacker to deface web pages or spread malware.

By reading this article and learning about the vulnerability in qdPM, users can take the necessary precautions to protect their digital assets. Those interested in further protecting their web applications can also utilize the pro features of the s4e.io platform. With features such as continuous monitoring and detailed reports on vulnerabilities and threats to web applications, users can better safeguard their online assets and prevent malicious attacks.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions users can take to protect against this vulnerability. The following bullet list includes some recommended actions:

  • Upgrade to the latest version of qdPM, as this vulnerability has been fixed in newer releases.
  • Avoid clicking on suspicious links or opening attachments from unknown sources.
  • Use security software, such as firewalls and antivirus programs, to detect and prevent malicious attacks.
  • Implement Content Security Policy (CSP) to aid in preventing XSS attacks.
  • Train employees on safe browsing habits, such as being cautious of downloading untrusted software and opening unknown emails.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-8390 scanner - Cross-Site Scripting (XSS) vulnerability in qdPM | S4E