The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.Referenceshttps://gist.github.com/NinjaXshell/be613dab99601f6abce884f6bc3d83a8https://www.exploit-db.com/exploits/44764/