GHSA-6r26-7hfr-q8rrMediumCVSS 5.3
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
🔗 CVE IDs covered (1)
📋 Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT, Consultancy Coop. Workcube ERP allows Reflected XSS.This issue affects Workcube ERP: from V12 - V14 through 20250916.
NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available.