Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qwe Labs
Qwe Labs qwe Dl |
|
| Vendors & Products |
Qwe Labs
Qwe Labs qwe Dl |
Mon, 02 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 01 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to inject malicious script code through path parameter manipulation. Attackers can exploit the vulnerability to execute persistent cross-site scripting attacks, potentially leading to session hijacking and application module manipulation. | |
| Title | QWE DL 2.0.1 Persistent XSS Vulnerability via Path Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-02T19:20:17.018Z
Reserved: 2026-01-10T01:51:52.984Z
Link: CVE-2023-54343
Updated: 2026-02-02T19:19:49.883Z
Status : Deferred
Published: 2026-02-01T13:15:58.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-54343
No data.
OpenCVE Enrichment
Updated: 2026-02-02T09:26:27Z