CVE-2018-17049: Cqu Lankers Project Cqu Lankers

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.

Affected products

Published 2018-09-14. Last modified 2026-06-17.