Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the RID parameter.
qpr portal