CVE-2023-7149: Code-Projects Qr Code Generator

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic. This affects an unknown part of the file /download.php?file=author.png. The manipulation of the argument file with the input "><iMg src=N onerror=alert(document.domain)> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249153 was assigned to this vulnerability.

Affected products

Published 2023-12-29. Last modified 2026-06-17.