PT-2019-15201 · Apak · Apak Wholesale Floorplanning Finance
Published
2019-10-31
·
Updated
2019-11-07
·
CVE-2019-17551
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apak Wholesale Floorplanning Finance versions 6.31.8.3 through 6.31.8.5
Description
The issue allows an attacker to send an authenticated POST request with a malicious payload to "/WFS/agreementView.faces" which enables a stored XSS via the
mainForm:loanNotesnotes:0:rich text editor note text parameter in the Notes section. All versions with the vulnerable WYSIWYG editor in the Notes section are likely affected.Recommendations
For versions 6.31.8.3 and 6.31.8.5, consider disabling the WYSIWYG editor in the Notes section until a patch is available.
Restrict access to the "/WFS/agreementView.faces" endpoint to minimize the risk of exploitation.
Avoid using the
mainForm:loanNotesnotes:0:rich text editor note text parameter in the affected API endpoint until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apak Wholesale Floorplanning Finance