Sceawere

Vulnerability Detail

CVE-2026-105069UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in QR Redirector

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
10h ago
Vendor
Nikki Blight
Product
QR Redirector
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from n/a through 2.0.5.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T09:17:11.423Z",
  "pubdate": "2026-10-05T09:17:11.423Z",
  "executiveSummary": "The QR Redirector plugin, developed by Nikki Blight, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis security flaw, identified as an Improper Neutralization of Input During Web Page Generation, enables an attacker to inject arbitrary malicious scripts into the application's database.\nThe vulnerability affects all versions of QR Redirector from n/a through 2.0.5.\nSuccessful exploitation occurs when a victim, typically an administrator, views the compromised data within the application interface.\nThe injected script executes within the context of the user's browser, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive information.\nThe risk is significant as it leverages the trust relationship between the user and the application, allowing for persistent malicious behavior without the need for constant interaction from the attacker after the initial injection.",
  "technicalDetails": "The vulnerability originates from a failure to perform adequate input sanitization and output encoding on user-supplied data before it is persisted in the database and subsequently rendered in the administrative dashboard.\nBy failing to neutralize special characters, the application allows the insertion of executable JavaScript payloads into fields processed by the QR Redirector plugin.\nThe attack flow typically begins with an attacker submitting a malicious script via an input field that the plugin processes. Because the application lacks robust server-side validation or output encoding mechanisms, the browser interprets the stored data as active content rather than plain text.\nWhen a legitimate user or administrator navigates to the affected page, the application fetches the tainted data from the database and renders it directly into the HTML document object model (DOM).\nUpon rendering, the web browser executes the embedded JavaScript in the security context of the user's session. This allows the attacker to perform operations such as executing commands, stealing session tokens, modifying page content, or redirecting the user to a malicious external site.\nThe vulnerability affects QR Redirector versions n/a through 2.0.5. Exploitation does not necessarily require authentication to the target system if the input vectors are exposed publicly, although it is more common for stored XSS to be triggered by users with specific administrative privileges who interact with the plugin's interface.\nThe impact is persistent, meaning the malicious payload remains active until the record is manually removed from the database or the vulnerable code path is remediated. Because the script executes in the user's browser, it inherits the permissions associated with the victim's session, potentially bypassing secondary security controls depending on the configuration of the web application environment."
}
CVE-2026-105069: Stored XSS in QR Redirector (MEDIUM Severity, CVSS: 6.5) | Sceawere