CVE-2018-14875: Polarisft Intellect Core Banking

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter.

Affected products

  • Polarisft Intellect Core Banking: version 9.7.1 only

Published 2019-04-30. Last modified 2026-06-17.