A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverterServlet` component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user's context. The affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version SE.2025.1.
Metrics
Affected Vendors & Products
References
History
Tue, 22 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 22 Jul 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverterServlet` component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user's context. The affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version SE.2025.1. | |
Title | ETQ Reliance CG Reflected Cross-Site Scripting in `SQLConverterServlet` | |
Weaknesses | CWE-116 CWE-79 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-22T12:35:57.509Z
Updated: 2025-07-22T13:21:50.982Z
Reserved: 2025-04-15T19:15:22.563Z
Link: CVE-2025-34141

Updated: 2025-07-22T13:21:41.442Z

Status : Awaiting Analysis
Published: 2025-07-22T13:15:24.827
Modified: 2025-07-25T15:29:44.523
Link: CVE-2025-34141

No data.