The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.haulmont.cuba:cuba-web-toolkit(Maven) | 6.10.0 | 6.10.7 | N/A |
| com.haulmont.cuba:cuba-web-toolkit(Maven) | 6.9.0 | 6.9.8 | N/A |
| com.haulmont.cuba:cuba-web-toolkit(Maven) | 0 | 6.8.15 | N/A |
CVSS Metrics