← Back to CVE List

CVE-2019-17551

Published: 2019-10-31T03:15Z
Last Modified: 2024-11-21T04:32Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the mainForm:loanNotesnotes:0:rich_text_editor_note_text parameter in the Notes section. Although versions 6.31.8.3 and 6.31.8.5 are confirmed to be affected, all versions with the vulnerable WYSIWYG editor in the Notes section are likely affected. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt