VYPR
Medium severity5.4OSV Advisory· Published Jan 3, 2019· Updated Jun 17, 2026

CVE-2018-20663

CVE-2018-20663

Description

The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.haulmont.cuba:cuba-web-toolkitMaven
>= 6.10.0, < 6.10.76.10.7
com.haulmont.cuba:cuba-web-toolkitMaven
>= 6.9.0, < 6.9.86.9.8
com.haulmont.cuba:cuba-web-toolkitMaven
< 6.8.156.8.15

Affected products

4

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.

CVE-2018-20663 · Medium · VYPR