CVE-2019-17551: Apakgroup Wholesale Floorplanning Finance

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the mainForm:loanNotesnotes:0:rich_text_editor_note_text parameter in the Notes section. Although versions 6.31.8.3 and 6.31.8.5 are confirmed to be affected, all versions with the vulnerable WYSIWYG editor in the Notes section are likely affected.

Affected products

  • Apakgroup Wholesale Floorplanning Finance: version 6.31.8.3 only; version 6.31.8.5 only

Published 2019-10-31. Last modified 2026-06-17.