Executive brief
QGIS QWC2 is a web-based client for viewing and interacting with GIS (geographic information system) maps and data. An authorized user can inject malicious JavaScript code through the attribute table feature, allowing them to steal session cookies, redirect users to phishing sites, or deface the application interface for other users.
Technical details
A cross-site scripting (CWE-79) vulnerability exists in the attribute table component of QGIS QWC2 prior to version 2025.08.14. The vulnerability allows an authenticated attacker with authorization to plant arbitrary JavaScript code that executes in the browser context of other users viewing the same attribute table. The attack requires user interaction (opening/viewing the affected table), but does not require network or adjacent access—only authentication. An attacker can achieve high confidentiality impact (session hijacking, data theft) with limited integrity impact. A patch is available in version 2025.08.14 and later.
Affected products
- QGIS QWC2 all versions prior to 2025.08.14
Timeline
- 2025-10-13: disclosed
- 2025-08-14: patched: Fix released in version 2025.08.14