An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site Scripting (XSS). Fixed in Release 24.2020.20608.0.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://excellium-services.com/cert-xlm-advisory/ | third party advisory |
https://halvotec.de/produkte/raquest/ | vendor advisory |
https://excellium-services.com/cert-xlm-advisory/cve-2019-19612/ | product third party advisory |