GHSA-6r26-7hfr-q8rrMediumCVSS 5.3

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...

Published
September 16, 2025
Last Modified
June 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT, Consultancy Coop. Workcube ERP allows Reflected XSS.This issue affects Workcube ERP: from V12 - V14 through 20250916. 

NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available.

🔗 References (4)