MEDIUM
QWE DL 2.0.1 Persistent XSS Vulnerability via Path Parameter
Published Feb 1, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.34%
Description
QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to inject malicious script code through path parameter manipulation. Attackers can exploit the vulnerability to execute persistent cross-site scripting attacks, potentially leading to session hijacking and application module manipulation.
Affected products
-
- Version 2.0.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://apps.apple.com/us/app/qwe/id935520103 product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-60536 Advisory
- https://www.vulncheck.com/advisories/qwe-dl-persistent-xss-vulnerability-via-path-parameter third-party-advisory
- https://www.vulnerability-lab.com/get_content.php?id=2326 exploit
| Link | Providers | Tags |
|---|---|---|
| https://apps.apple.com/us/app/qwe/id935520103 | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-60536 | Advisory | |
| https://www.vulncheck.com/advisories/qwe-dl-persistent-xss-vulnerability-via-path-parameter | third-party-advisory | |
| https://www.vulnerability-lab.com/get_content.php?id=2326 | exploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Feb 1, 2026
Updated Feb 2, 2026
Reserved Jan 10, 2026
Link CVE-2023-54343
CISA Vulnrichment
Updated Feb 2, 2026
ENISA EUVD
EUVD-2023-60536 Assigner VulnCheck
Published Feb 1, 2026
Updated Feb 2, 2026
Exploited since n/a
Link EUVD-2023-60536