CVE detail
CVE-2019-17551 — CVE-2019-17551
Published 2019-10-31 · Modified 2026-06-17 · Vendor apakgroup · Product wholesale_floorplanning_finance · Source nvd
MEDIUM
severity
CVSS-derived band
0.0066
EPSS probability
exploitation probability, 30d
48.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the mainForm:loanNotesnotes:0:rich_text_editor_note_text parameter in the Notes section. Although versions 6.31.8.3 and 6.31.8.5 are confirmed to be affected, all versions with the vulnerable WYSIWYG editor in the Notes section are likely affected.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References