Medium severity5.4OSV Advisory· Published Jan 3, 2019· Updated Jun 17, 2026
CVE-2018-20663
CVE-2018-20663
Description
The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.haulmont.cuba:cuba-web-toolkitMaven | >= 6.10.0, < 6.10.7 | 6.10.7 |
com.haulmont.cuba:cuba-web-toolkitMaven | >= 6.9.0, < 6.9.8 | 6.9.8 |
com.haulmont.cuba:cuba-web-toolkitMaven | < 6.8.15 | 6.8.15 |
Affected products
4- Range: 6.10.0, 6.10.0-BETA1, 6.10.0.BETA1, …
Patches
Vulnerability mechanics
References
7- github.com/cuba-platform/reports/issues/140nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-rff7-964g-pppxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-20663ghsaADVISORY
- github.com/cuba-platform/cuba/commit/be6aa41ff36a365e2a995d37861e5acfcd32c2c5ghsaWEB
- github.com/cuba-platform/cuba/commit/e9f972beeae42dc6dbc3aaa6b6ecc9814c0eedb4ghsaWEB
- github.com/cuba-platform/cuba/commit/ec8784d8f596aa570604f4e5d5d4a7c3ae264c62ghsaWEB
- github.com/cuba-platform/cuba/issues/1741ghsaWEB
News mentions
0No linked articles in our index yet.